In the Linux kernel, the following vulnerability has been resolved:
iommu/arm-smmu: Fix arm_smmu_device refcount leak when arm_smmu_rpm_get fails
arm_smmu_rpm_get() invokes pm_runtime_get_sync(), which increases the refcount of the "smmu" even though the return value is less than 0.
The reference counting issue happens in some error handling paths of arm_smmu_rpm_get() in its caller functions. When arm_smmu_rpm_get() fails, the caller functions forget to decrease the refcount of "smmu" increased by arm_smmu_rpm_get(), causing a refcount leak.
Fix this issue by calling pm_runtime_resume_and_get() instead of pm_runtime_get_sync() in arm_smmu_rpm_get(), which can keep the refcount balanced in case of failure.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47327.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.4.134"
}
]
},
{
"events": [
{
"introduced": "5.5"
},
{
"fixed": "5.10.52"
}
]
},
{
"events": [
{
"introduced": "5.11"
},
{
"fixed": "5.12.19"
}
]
},
{
"events": [
{
"introduced": "5.13"
},
{
"fixed": "5.13.4"
}
]
}
]