CVE Database
/

CVE-2021-47024

Back to search

CVE-2021-47024

Published: Feb 28, 2024

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: free queued packets when closing socket As reported by syzbot [1], there is a memory leak while closing the socket. We partially solved this issue with commit ac03046ece2b ("vsock/virtio: free packets during the socket release"), but we forgot to drain the RX queue when the socket is definitely closed by the scheduled work. To avoid future issues, let's use the new virtio_transport_remove_sock() to drain the RX queue before removing the socket from the af_vsock lists calling vsock_remove_sock(). [1] https://syzkaller.appspot.com/bug?extid=24452624fc4c571eedd9

VendorProductVersions

Linux

Linux

affected
ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 - < b605673b523fe33abeafb2136759bcbc9c1e6ebf
affected
ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 - < 27691665145e74a45034a9dccf1150cf1894763a
affected
ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 - < 37c38674ef2f8d7e8629e5d433c37d6c1273d16b
affected
ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 - < 8432b8114957235f42e070a16118a7f750de9d39
affected
4ea082cd3c400cd5bb36a7beb7e441bf3e29350d

+9 more versions

Linux

Linux

affected
5.2
unaffected
0 - < 5.2
unaffected
5.10.37 - <= 5.10.*
unaffected
5.11.21 - <= 5.11.*
unaffected
5.12.4 - <= 5.12.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now