CVE-2021-47671

Analyzed
Published: 17 Apr 2025, 18:01
Last modified:11 May 2026, 13:58

Vulnerability Summary

Overall Risk (default)
low
13/100
CVSS Score
3.3 LOW
v3.1 (cve.org)
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Apr 2025, 18:01
Published
Vulnerability first disclosed
11 May 2026, 13:58
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling netif_rx(skb). This means that the skb previously allocated by alloc_can_err_skb() is not freed. In other terms, this is a memory leak. This patch simply removes the return statement in the error branch and let the function continue. Issue was found with GCC -fanalyzer, please follow the link below for details.

CVSS Metrics

  • v3.1LOWScore: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 0.03% Percentile: 8%

Techniques & Countermeasures

  • CWE-401Missing Release of Memory after Effective Lifetime

    The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Affected Systems

  • linuxlinux

    ≥ 8537257874e949a59c834cecfd5a063e11b64b0b, < 4f389e1276a5389c92cef860c9fde8e1c802a871 | ≥ 8537257874e949a59c834cecfd5a063e11b64b0b, < 7eb0881aec26099089f12ae850aebd93190b1dfe | ≥ 8537257874e949a59c834cecfd5a063e11b64b0b, < d9447f768bc8c60623e4bb3ce65b8f4654d33a50 | 5.13

  • linuxlinux_kernel

    ≥ 5.13, < 5.14.19 | ≥ 5.15, < 5.15.3

References (3)