CVE-2021-47367

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix pages leaking when building skb in big mode We try to use build_skb() if we had sufficient tailroom. But we forget to release the unused pages chained via private in big mode which will leak pages. Fixing this by release the pages after building the skb in big mode.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*

History

02 Apr 2025, 14:53

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/afd92d82c9d715fb97565408755acad81573591a - () https://git.kernel.org/stable/c/afd92d82c9d715fb97565408755acad81573591a - Patch
References () https://git.kernel.org/stable/c/f020bb63b5d2e5576acadd10e158fe3b04af67ba - () https://git.kernel.org/stable/c/f020bb63b5d2e5576acadd10e158fe3b04af67ba - Patch
CPE cpe:2.3:o:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux

21 Nov 2024, 06:35

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/afd92d82c9d715fb97565408755acad81573591a - () https://git.kernel.org/stable/c/afd92d82c9d715fb97565408755acad81573591a -
References () https://git.kernel.org/stable/c/f020bb63b5d2e5576acadd10e158fe3b04af67ba - () https://git.kernel.org/stable/c/f020bb63b5d2e5576acadd10e158fe3b04af67ba -

03 Jul 2024, 01:37

Type Values Removed Values Added
CWE CWE-119
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: virtio-net: corrige páginas con fugas al compilar skb en modo grande. Intentamos usar build_skb() si tuviéramos suficiente espacio de adaptación. Pero nos olvidamos de liberar las páginas no utilizadas encadenadas vía privada en modo grande, lo que filtrará páginas. Para solucionar este problema, libere las páginas después de compilar el skb en modo grande.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

21 May 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-21 15:15

Updated : 2025-04-02 14:53


NVD link : CVE-2021-47367

Mitre link : CVE-2021-47367

CVE.ORG link : CVE-2021-47367


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer