CVE-2021-47655

medium

Description

In the Linux kernel, the following vulnerability has been resolved: media: venus: vdec: fixed possible memory leak issue The venus_helper_alloc_dpb_bufs() implementation allows an early return on an error path when checking the id from ida_alloc_min() which would not release the earlier buffer allocation. Move the direct kfree() from the error checking of dma_alloc_attrs() to the common fail path to ensure that allocations are released on all error paths in this function. Addresses-Coverity: 1494120 ("Resource leak")

References

https://git.kernel.org/stable/c/8403fdd775858a7bf04868d43daea0acbe49ddfc

https://git.kernel.org/stable/c/5f89d05ba93df9c2cdfe493843f93288e55e99eb

https://git.kernel.org/stable/c/5cedfe8aaf1875a5305897107b7f298db4260019

https://git.kernel.org/stable/c/55bccafc246b2e64763a155ec454470c07a54a6e

Details

Source: Mitre, NVD

Published: 2025-02-26

Updated: 2025-03-18

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00015