U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-47655

Change History

New CVE Received from kernel.org 2/26/2025 1:37:07 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

media: venus: vdec: fixed possible memory leak issue

The venus_helper_alloc_dpb_bufs() implementation allows an early return
on an error path when checking the id from ida_alloc_min() which would
not release the earlier buffer allocation.

Move the direct kfree() from the error checking of dma_alloc_attrs() to
the common fail path to ensure that allocations are released on all
error paths in this function.

Addresses-Coverity: 1494120 ("Resource leak")
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/55bccafc246b2e64763a155ec454470c07a54a6e
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/5cedfe8aaf1875a5305897107b7f298db4260019
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/5f89d05ba93df9c2cdfe493843f93288e55e99eb
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/8403fdd775858a7bf04868d43daea0acbe49ddfc