
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47499 affects the Linux kernel's Industrial I/O (IIO) subsystem, specifically in the KXCJK-1013 accelerometer driver. The vulnerability was discovered in May 2024 and involves a memory leak condition when handling ACPI_SMO8500 type devices (NVD).
The vulnerability occurs when the ACPI type is ACPI_SMO8500, where data->dready_trig is not set, causing memory allocated by iio_triggered_buffer_setup() to remain unreleased. This results in a memory leak of 512 bytes, as demonstrated by the unreferenced object at address 0xffff888009551400. The issue has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).
The vulnerability leads to memory leaks in the Linux kernel when using the affected KXCJK-1013 accelerometer driver with ACPI_SMO8500 type devices. While this doesn't pose immediate security risks, it can result in gradual system resource depletion over time (NVD).
The vulnerability requires local access with low privileges to exploit. There are no known instances of this vulnerability being exploited in the wild (NVD).
The issue has been fixed by removing the data->dready_trig condition in probe and remove functions. The fix has been implemented across multiple kernel versions, including patches for Linux kernel versions from 4.2 through 5.15.8. Users should update to patched kernel versions (Kernel Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."