CVE-2021-47659 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/plane: Move range check for format_count earlier While the check for format_count > 64 in __drm_universal_plane_init() shouldn't be hit (it's a WARN_ON), in its current position it will then leak the plane->format_types array and fail to call drm_mode_object_unregister() leaking the modeset identifier. Move it to the start of the function to avoid allocating those resources in the first place.
A vulnerability in the Linux kernel's handling of universal planes in the Direct Rendering Manager (DRM) can lead to a resource leak. The issue arises in the __drm_universal_plane_init() function, where a range check for the format_count parameter is currently positioned after the resource allocation. This oversight can cause the format_types array to be leaked and fail to properly unregister the mode object, resulting in a leak of the modeset identifier. By moving the range check to the beginning of the function, the vulnerability can be mitigated before allocating resources.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1e29d829ad51d1472dd035487953a6724b56fc33 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4ab7e453a3ee88c274cf97bee9487ab92a66d313 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4b674dd69701c2e22e8e7770c1706a69f3b17269 | kernel.org | Patch |
| https://git.kernel.org/stable/c/787163d19bc3cdc6ca4b96223f62208534d1cf6b | kernel.org | Patch |
| https://git.kernel.org/stable/c/978e3d023256bfaf34a0033d40c94e8a8e70cf3c | kernel.org | Patch |
| https://git.kernel.org/stable/c/ad6dd7a2bac86118985c7b3426e175b9d3c1ec4f | kernel.org | Patch |
| https://git.kernel.org/stable/c/b5cd108143513e4498027b96ec4710702d186f11 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.14, < 4.19.247 >= 4.20, < 5.4.198 >= 5.5, < 5.10.121 >= 5.11, < 5.15.46 >= 5.16, < 5.17.14 >= 5.18, < 5.18.3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Oct 14, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | kernel.org |