{"id":"DEBIAN-CVE-2021-46956","details":"In the Linux kernel, the following vulnerability has been resolved:  virtiofs: fix memory leak in virtio_fs_probe()  When accidentally passing twice the same tag to qemu, kmemleak ended up reporting a memory leak in virtiofs.  Also, looking at the log I saw the following error (that's when I realised the duplicated tag):    virtiofs: probe of virtio5 failed with error -17  Here's the kmemleak log for reference:  unreferenced object 0xffff888103d47800 (size 1024):   comm \"systemd-udevd\", pid 118, jiffies 4294893780 (age 18.340s)   hex dump (first 32 bytes):     00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00  .....N..........     ff ff ff ff ff ff ff ff 80 90 02 a0 ff ff ff ff  ................   backtrace:     [\u003c000000000ebb87c1\u003e] virtio_fs_probe+0x171/0x7ae [virtiofs]     [\u003c00000000f8aca419\u003e] virtio_dev_probe+0x15f/0x210     [\u003c000000004d6baf3c\u003e] really_probe+0xea/0x430     [\u003c00000000a6ceeac8\u003e] device_driver_attach+0xa8/0xb0     [\u003c00000000196f47a7\u003e] __driver_attach+0x98/0x140     [\u003c000000000b20601d\u003e] bus_for_each_dev+0x7b/0xc0     [\u003c00000000399c7b7f\u003e] bus_add_driver+0x11b/0x1f0     [\u003c0000000032b09ba7\u003e] driver_register+0x8f/0xe0     [\u003c00000000cdd55998\u003e] 0xffffffffa002c013     [\u003c000000000ea196a2\u003e] do_one_initcall+0x64/0x2e0     [\u003c0000000008f727ce\u003e] do_init_module+0x5c/0x260     [\u003c000000003cdedab6\u003e] __do_sys_finit_module+0xb5/0x120     [\u003c00000000ad2f48c6\u003e] do_syscall_64+0x33/0x40     [\u003c00000000809526b5\u003e] entry_SYSCALL_64_after_hwframe+0x44/0xae","modified":"2026-09-15T09:02:30.475763407Z","published":"2024-02-27T19:04:06.717Z","upstream":["CVE-2021-46956"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-46956"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46956.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46956.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46956.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}