CVE-2021-4028

CVSS v3.1 7.8 (High)
78% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 2
Advisories 13

A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-08-24 16:15:09
(2 years ago)
Updated Date
2023-02-10 16:18:15
(19 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 5.10 version and prior 5.10.71 version cpe:2.3:o:linux:linux_kernel >= 5.10 < 5.10.71
  Linux Kernel from 5.11 version and prior 5.14.10 version cpe:2.3:o:linux:linux_kernel >= 5.11 < 5.14.10

Configuration #2

    CPE23 From Up To
  Suse Linux Enterprise 15.0 SP3 cpe:2.3:o:suse:linux_enterprise:15.0:sp3
  Suse Linux Enterprise 15.0 SP4 cpe:2.3:o:suse:linux_enterprise:15.0:sp4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...