IT

Tracker / CVE-2021-47058

CVE-2021-47058

High 7.8

In the Linux kernel, the following vulnerability has been resolved: regmap: set debugfs_name to NULL after it is freed There is a upstream commit cffa4b2122f5("regmap:debugfs: Fix a memory leak when calling regmap_attach_dev") that adds a if condition when create name for debugfs_name. With below function invoking logical, debugfs_name is freed in regmap_debugfs_exit(), but it is not created again because of the if condition introduced by above commit. regmap_reinit_cache() regmap_debugfs_exit() ... regmap_debugfs_init() So, set debugfs_name to NULL after it is freed.

Affected products and versions

linux linux_kernel · 4.19.168 → 4.19.191
linux linux_kernel · 5.10.8 → 5.10.37
linux linux_kernel · 5.11 → 5.11.21
linux linux_kernel · 5.12 → 5.12.4
linux linux_kernel · 5.4.90 → 5.4.119

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References