{"id":"DEBIAN-CVE-2021-47238","details":"In the Linux kernel, the following vulnerability has been resolved:  net: ipv4: fix memory leak in ip_mc_add1_src  BUG: memory leak unreferenced object 0xffff888101bc4c00 (size 32):   comm \"syz-executor527\", pid 360, jiffies 4294807421 (age 19.329s)   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................     01 00 00 00 00 00 00 00 ac 14 14 bb 00 00 02 00 ................   backtrace:     [\u003c00000000f17c5244\u003e] kmalloc include/linux/slab.h:558 [inline]     [\u003c00000000f17c5244\u003e] kzalloc include/linux/slab.h:688 [inline]     [\u003c00000000f17c5244\u003e] ip_mc_add1_src net/ipv4/igmp.c:1971 [inline]     [\u003c00000000f17c5244\u003e] ip_mc_add_src+0x95f/0xdb0 net/ipv4/igmp.c:2095     [\u003c000000001cb99709\u003e] ip_mc_source+0x84c/0xea0 net/ipv4/igmp.c:2416     [\u003c0000000052cf19ed\u003e] do_ip_setsockopt net/ipv4/ip_sockglue.c:1294 [inline]     [\u003c0000000052cf19ed\u003e] ip_setsockopt+0x114b/0x30c0 net/ipv4/ip_sockglue.c:1423     [\u003c00000000477edfbc\u003e] raw_setsockopt+0x13d/0x170 net/ipv4/raw.c:857     [\u003c00000000e75ca9bb\u003e] __sys_setsockopt+0x158/0x270 net/socket.c:2117     [\u003c00000000bdb993a8\u003e] __do_sys_setsockopt net/socket.c:2128 [inline]     [\u003c00000000bdb993a8\u003e] __se_sys_setsockopt net/socket.c:2125 [inline]     [\u003c00000000bdb993a8\u003e] __x64_sys_setsockopt+0xba/0x150 net/socket.c:2125     [\u003c000000006a1ffdbd\u003e] do_syscall_64+0x40/0x80 arch/x86/entry/common.c:47     [\u003c00000000b11467c4\u003e] entry_SYSCALL_64_after_hwframe+0x44/0xae  In commit 24803f38a5c0 (\"igmp: do not remove igmp souce list info when set link down\"), the ip_mc_clear_src() in ip_mc_destroy_dev() was removed, because it was also called in igmpv3_clear_delrec().  Rough callgraph:  inetdev_destroy -\u003e ip_mc_destroy_dev      -\u003e igmpv3_clear_delrec         -\u003e ip_mc_clear_src -\u003e RCU_INIT_POINTER(dev-\u003eip_ptr, NULL)  However, ip_mc_clear_src() called in igmpv3_clear_delrec() doesn't release in_dev-\u003emc_list-\u003esources. And RCU_INIT_POINTER() assigns the NULL to dev-\u003eip_ptr. As a result, in_dev cannot be obtained through inetdev_by_index() and then in_dev-\u003emc_list-\u003esources cannot be released by ip_mc_del1_src() in the sock_close. Rough call sequence goes like:  sock_close -\u003e __sock_release    -\u003e inet_release       -\u003e ip_mc_drop_socket          -\u003e inetdev_by_index          -\u003e ip_mc_leave_src             -\u003e ip_mc_del_src                -\u003e ip_mc_del1_src  So we still need to call ip_mc_clear_src() in ip_mc_destroy_dev() to free in_dev-\u003emc_list-\u003esources.","modified":"2026-09-15T09:02:35.409898027Z","published":"2024-05-21T15:15:13.017Z","upstream":["CVE-2021-47238"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47238"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47238.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47238.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47238.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}