In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Use after free in _vmbusopen()
The "openinfo" variable is added to the &vmbusconnection.chnmsglist, but the error handling frees "open_info" without removing it from the list. This will result in a use after free. First remove it from the list, and then free it.
[
{
"events": [
{
"introduced": "4.14"
},
{
"fixed": "5.10.37"
}
]
},
{
"events": [
{
"introduced": "5.11"
},
{
"fixed": "5.11.21"
}
]
},
{
"events": [
{
"introduced": "5.12"
},
{
"fixed": "5.12.4"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-47049.json"