CVE-2021-47361

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-47361
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-47361.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-47361
Downstream
Related
Published
2024-05-21T15:15:22Z
Modified
2025-08-09T20:01:25Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

mcb: fix error handling in mcballocbus()

There are two bugs: 1) If idasimpleget() fails then this code calls putdevice(carrier) but we haven't yet called getdevice(carrier) and probably that leads to a use after free. 2) After deviceinitialize() then we need to use putdevice() to release the bus. This will free the internal resources tied to the device and call mcbfreebus() which will free the rest.

References

Affected packages