CVE-2021-47671

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling netif_rx(skb). This means that the skb previously allocated by alloc_can_err_skb() is not freed. In other terms, this is a memory leak. This patch simply removes the return statement in the error branch and let the function continue. Issue was found with GCC -fanalyzer, please follow the link below for details.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Apr 2025, 18:40

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/4f389e1276a5389c92cef860c9fde8e1c802a871 - () https://git.kernel.org/stable/c/4f389e1276a5389c92cef860c9fde8e1c802a871 - Patch
References () https://git.kernel.org/stable/c/7eb0881aec26099089f12ae850aebd93190b1dfe - () https://git.kernel.org/stable/c/7eb0881aec26099089f12ae850aebd93190b1dfe - Patch
References () https://git.kernel.org/stable/c/d9447f768bc8c60623e4bb3ce65b8f4654d33a50 - () https://git.kernel.org/stable/c/d9447f768bc8c60623e4bb3ce65b8f4654d33a50 - Patch
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: can: etas_es58x: es58x_rx_err_msg(): corrige pérdida de memoria en la ruta de error. En es58x_rx_err_msg(), si can->do_set_mode() falla, la función retorna directamente sin llamar a netif_rx(skb). Esto significa que el skb previamente asignado por alloc_can_err_skb() no se libera. En otras palabras, se trata de una pérdida de memoria. Este parche simplemente elimina la instrucción de retorno en la rama de error y permite que la función continúe. Se encontró un problema con GCC -fanalyzer; siga el enlace a continuación para obtener más información.
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

17 Apr 2025, 20:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CWE CWE-401

17 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 18:15

Updated : 2025-04-21 18:40


NVD link : CVE-2021-47671

Mitre link : CVE-2021-47671

CVE.ORG link : CVE-2021-47671


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime