CVE-2021-47074

MEDIUM

Linux Kernel - Use-After-Free in nvme_loop_create_ctrl()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-loop: fix memory leak in nvme_loop_create_ctrl() When creating loop ctrl in nvme_loop_create_ctrl(), if nvme_init_ctrl() fails, the loop ctrl should be freed before jumping to the "out" label.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (10)
Linux/Linux < 4.8
Linux/Linux 3a85a5de29ea779634ddfd768059e06196687aba - 03504e3b54cc8118cc26c064e60a0b00c2308708
Linux/Linux 3a85a5de29ea779634ddfd768059e06196687aba - 551ba08d4b7eb26f75758cdb9f15105b276517ad
Linux/Linux 3a85a5de29ea779634ddfd768059e06196687aba - 9c980795ccd77e8abec33dd6fe28dfe1c4083e65
Linux/Linux 4.8
Linux/Linux 5.10.40 - 5.10.*
Linux/Linux 5.12.7 - 5.12.*
Linux/Linux 5.13
linux/linux_kernel 5.13 rc1 (2 CPE variants)
linux/linux_kernel 4.8 - 5.10.40
Published Mar 01, 2024
Tracked Since Feb 18, 2026