#VU90042 Memory leak in Linux kernel - CVE-2021-46944
Published: May 30, 2024 / Updated: May 14, 2025
Vulnerability identifier: #VU90042
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-46944
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the imgu_fmt() function in drivers/staging/media/ipu3/ipu3-v4l2.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
External links
- https://git.kernel.org/stable/c/ff792ae52005c85a2d829c153e08d99a356e007d
- https://git.kernel.org/stable/c/517f6f570566a863c2422b843c8b7d099474f6a9
- https://git.kernel.org/stable/c/14d0e99c3ef6b0648535a31bf2eaabb4eff97b9e
- https://git.kernel.org/stable/c/74ba0adb5e983503b18a96121d965cad34ac7ce3
- https://git.kernel.org/stable/c/3630901933afba1d16c462b04d569b7576339223
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.36
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.20
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.118