CVE-2021-47177

MEDIUM

Linux Kernel 4.11-4.14.235 - Use-After-Free in IOMMU VT-d Sysfs Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix sysfs leak in alloc_iommu() iommu_device_sysfs_add() is called before, so is has to be cleaned on subsequent errors.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (16)
Linux/Linux < 4.11
Linux/Linux 39ab9555c24110671f8dc671311a26e5c985b592 - 044bbe8b92ab4e542de7f6c93c88ea65cccd8e29
Linux/Linux 39ab9555c24110671f8dc671311a26e5c985b592 - 0ee74d5a48635c848c20f152d0d488bf84641304
Linux/Linux 39ab9555c24110671f8dc671311a26e5c985b592 - 22da9f4978381a99f1abaeaf6c9b83be6ab5ddd8
Linux/Linux 39ab9555c24110671f8dc671311a26e5c985b592 - 2ec5e9bb6b0560c90d315559c28a99723c80b996
Linux/Linux 39ab9555c24110671f8dc671311a26e5c985b592 - ca466561eef36d1ec657673e3944eb6340bddb5b
Linux/Linux 39ab9555c24110671f8dc671311a26e5c985b592 - f01134321d04f47c718bb41b799bcdeda27873d2
Linux/Linux 4.11
Linux/Linux 4.14.235 - 4.14.*
Linux/Linux 4.19.193 - 4.19.*
... and 6 more
Published Mar 25, 2024
Tracked Since Feb 18, 2026