ZeroHour

CVE-2021-47344

CVSS 3.1
5.5 medium
EPSS
<1%p16
Published
()
Modified
Description

In the Linux kernel, the following vulnerability has been resolved: media: zr364xx: fix memory leak in zr364xx_start_readpipe syzbot reported memory leak in zr364xx driver. The problem was in non-freed urb in case of usb_submit_urb() fail. backtrace: [ ] kmalloc include/linux/slab.h:561 [inline] [ ] usb_alloc_urb+0x66/0xe0 drivers/usb/core/urb.c:74 [ ] zr364xx_start_readpipe+0x78/0x130 drivers/media/usb/zr364xx/zr364xx.c:1022 [ ] zr364xx_board_init drivers/media/usb/zr364xx/zr364xx.c:1383 [inline] [ ] zr364xx_probe+0x6a3/0x851 drivers/media/usb/zr364xx/zr364xx.c:1516 [ ] usb_probe_interface+0x177/0x370 drivers/usb/core/driver.c:396 [ ] really_probe+0x159/0x500 drivers/base/dd.c:576

Vendors
linux
Products
linux kernel
Weakness
CWE-401
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.