LiveActive security incident?Get immediate response
CVE Record

CVE-2021-47173: misc/uss720: fix memory leak in uss720_probe

In the Linux kernel, the following vulnerability has been resolved: misc/uss720: fix memory leak in uss720_probe uss720_probe forgets to decrease the refcount of usbdev in uss720_probe. Fix this by decreasing the refcount of usbdev by usb_put_dev. BUG: memory leak unreferenced object 0xffff888101113800 (size 2048): comm "kworker/0:1", pid 7, jiffies 4294956777 (age 28.870s) hex dump (first 32 bytes): ff ff ff ff 31 00 00 00 00 00 00 00 00 00 00 00 ....1........... 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 ................ backtrace: [<ffffffff82b8e822>] kmalloc include/linux/slab.h:554 [inline] [<ffffffff82b8e822>] kzalloc include/linux/slab.h:684 [inline] [<ffffffff82b8e822>] usb_alloc_dev+0x32/0x450 drivers/usb/core/usb.c:582 [<ffffffff82b98441>] hub_port_connect drivers/usb/core/hub.c:5129 [inline] [<ffffffff82b98441>] hub_port_connect_change drivers/usb/core/hub.c:5363 [inline] [<ffffffff82b98441>] port_event drivers/usb/core/hub.c:5509 [inline] [<ffffffff82b98441>] hub_event+0x1171/0x20c0 drivers/usb/core/hub.c:5591 [<ffffffff81259229>] process_one_work+0x2c9/0x600 kernel/workqueue.c:2275 [<ffffffff81259b19>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2421 [<ffffffff81261228>] kthread+0x178/0x1b0 kernel/kthread.c:292 [<ffffffff8100227f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:294

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2021-47173 is a Linux kernel memory leak in the uss720 USB driver probe path. The published record says the driver failed to release a USB device reference, and kernel stable commits fix it. No CVSS score, severity, or active exploitation evidence is provided.

Executive priority

Treat this as routine kernel hygiene unless affected systems rely on the uss720 driver or cannot be patched. There is no supplied evidence of active exploitation or high-impact remote compromise, but unresolved kernel memory leaks still warrant normal update cycles.

Technical view

The issue is in misc/uss720: uss720_probe increments or holds a usbdev reference but fails to drop it. The fix calls usb_put_dev to reduce the reference count and prevent leaked usb_alloc_dev memory. The source bundle does not describe privilege requirements, attack vector, or security impact beyond memory leak.

Likely exposure

Exposure is most relevant to Linux systems running affected kernel versions with the uss720 driver path reachable. The source bundle lists Linux as affected and provides stable kernel fixes, but does not identify distributions, configurations, or whether the driver must be loaded.

Exploitation context

The CVE is not marked KEV, and the supplied sources do not report active exploitation. The record includes a kernel memory-leak trace, but no exploitability details, public exploit status, or remote attack claim.

Researcher notes

The record is narrow: missing usb_put_dev in uss720_probe causes a reference leak. Analysis should focus on kernel version lineage, distribution backports, and whether uss720 probe can be reached in the environment. Do not infer broader impact without vendor evidence.

Mitigation direction

  • Identify Linux kernels in the affected ranges from asset inventory.
  • Check vendor or distribution advisories for patched kernel packages.
  • Prioritize applying kernel stable updates containing the referenced uss720 fix.
  • If patching is delayed, review whether uss720 is needed on exposed systems.

Validation and detection

  • Confirm deployed kernel versions against the affected and fixed version information.
  • Verify vendor kernels include one of the referenced stable fixes or equivalent backport.
  • Check whether the uss720 driver is present, loadable, or in use.
  • Review vulnerability scanner findings for distribution-specific package status.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-47173 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux0f36163d3abefbda1b21a330b3fdf3c2dc076d94, 0f36163d3abefbda1b21a330b3fdf3c2dc076d94, 0f36163d3abefbda1b21a330b3fdf3c2dc076d94, 0f36163d3abefbda1b21a330b3fdf3c2dc076d94, 0f36163d3abefbda1b21a330b3fdf3c2dc076d94, 0f36163d3abefbda1b21a330b3fdf3c2dc076d94, 0f36163d3abefbda1b21a330b3fdf3c2dc076d94, 0f36163d3abefbda1b21a330b3fdf3c2dc076d94unaffected
LinuxLinux2.6.14, 0, 4.4.271, 4.9.271, 4.14.235, 4.19.193, 5.4.124, 5.10.42, 5.12.9, 5.13affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.