PT-2024-11247 · Linux+2 · Linux Kernel+2
Dongliang Mu
·
Published
2021-06-16
·
Updated
2025-06-18
·
CVE-2021-47239
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a possible use-after-free in the
smsc75xx bind function. The commit 46a8b29c6306 ("net: usb: fix memory leak in smsc75xx bind") fails to clean up the work scheduled in smsc75xx reset->smsc75xx set multicast, which leads to use-after-free if the work is scheduled to start after the deallocation. In addition, this patch also removes a dangling pointer - dev->data[0]. The patch calls cancel work sync to cancel the scheduled work and set the dangling pointer to NULL.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse