CVE-2021-4083

CVSS v3.1 7 (High)
70% Progress
CVSS v2.0 6.9 (Medium)
69% Progress
EPSS 0.04 % (10th)
0.04% Progress
Affected Products 23
Advisories 44

A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-01-18 17:15:09
(2 years ago)
Updated Date
2023-10-06 18:05:43
(11 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 4.4.294 version cpe:2.3:o:linux:linux_kernel < 4.4.294
  Linux Kernel from 4.5 version and prior 4.9.292 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.9.292
  Linux Kernel from 4.10 version and prior 4.14.257 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.257
  Linux Kernel from 4.15 version and prior 4.19.220 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.19.220
  Linux Kernel from 4.20 version and prior 5.4.164 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.4.164
  Linux Kernel from 5.5.0 version and prior 5.10.84 version cpe:2.3:o:linux:linux_kernel >= 5.5.0 < 5.10.84
  Linux Kernel from 5.11 version and prior 5.15.7 version cpe:2.3:o:linux:linux_kernel >= 5.11 < 5.15.7
  Linux Kernel 5.16 Rc1 cpe:2.3:o:linux:linux_kernel:5.16:rc1
  Linux Kernel 5.16 Rc2 cpe:2.3:o:linux:linux_kernel:5.16:rc2
  Linux Kernel 5.16 Rc3 cpe:2.3:o:linux:linux_kernel:5.16:rc3

Configuration #2

AND
    CPE23 From Up To
OR  
  Netapp H410c Firmware cpe:2.3:o:netapp:h410c_firmware:-
OR  
  Running on/with
  Netapp H410c cpe:2.3:h:netapp:h410c:-

Configuration #3

AND
    CPE23 From Up To
OR  
  Netapp H300s Firmware cpe:2.3:o:netapp:h300s_firmware:-
OR  
  Running on/with
  Netapp H300s cpe:2.3:h:netapp:h300s:-

Configuration #4

AND
    CPE23 From Up To
OR  
  Netapp H500s Firmware cpe:2.3:o:netapp:h500s_firmware:-
OR  
  Running on/with
  Netapp H500s cpe:2.3:h:netapp:h500s:-

Configuration #5

AND
    CPE23 From Up To
OR  
  Netapp H700s Firmware cpe:2.3:o:netapp:h700s_firmware:-
OR  
  Running on/with
  Netapp H700s cpe:2.3:h:netapp:h700s:-

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp H300e Firmware cpe:2.3:o:netapp:h300e_firmware:-
OR  
  Running on/with
  Netapp H300e cpe:2.3:h:netapp:h300e:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp H500e Firmware cpe:2.3:o:netapp:h500e_firmware:-
OR  
  Running on/with
  Netapp H500e cpe:2.3:h:netapp:h500e:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp H700e Firmware cpe:2.3:o:netapp:h700e_firmware:-
OR  
  Running on/with
  Netapp H700e cpe:2.3:h:netapp:h700e:-

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H410s Firmware cpe:2.3:o:netapp:h410s_firmware:-
OR  
  Running on/with
  Netapp H410s cpe:2.3:h:netapp:h410s:-

Configuration #10

    CPE23 From Up To
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #11

    CPE23 From Up To
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-

Configuration #12

    CPE23 From Up To
  Oracle Communications Cloud Native Core Binding Support Function 22.1.3 cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3
  Oracle Communications Cloud Native Core Network Exposure Function 22.1.1 cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.1
  Oracle Communications Cloud Native Core Policy 22.2.0 cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.2.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...