CVE-2021-4203

CVSS v3.1 6.8 (Medium)
68% Progress
CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.16 % (54th)
0.16% Progress
Affected Products 23
Advisories 28

A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-03-25 19:15:09
(2 years ago)
Updated Date
2023-11-07 03:40:21
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 5.15 version cpe:2.3:o:linux:linux_kernel < 5.15
  Linux Kernel 5.15 cpe:2.3:o:linux:linux_kernel:5.15:-
  Linux Kernel 5.15 Rc1 cpe:2.3:o:linux:linux_kernel:5.15:rc1
  Linux Kernel 5.15 Rc2 cpe:2.3:o:linux:linux_kernel:5.15:rc2
  Linux Kernel 5.15 Rc3 cpe:2.3:o:linux:linux_kernel:5.15:rc3

Configuration #2

    CPE23 From Up To
  Netapp Active Iq Unified Manager for Vmware Vsphere cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere
  Netapp E-series Santricity Os Controller from 11.0.0 version and 11.70.2 and prior versions cpe:2.3:a:netapp:e-series_santricity_os_controller >= 11.0.0 <= 11.70.2
  Netapp Element Software cpe:2.3:a:netapp:element_software:-
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-

Configuration #3

AND
    CPE23 From Up To
OR  
  Netapp Bootstrap Os cpe:2.3:o:netapp:bootstrap_os:-
OR  
  Running on/with
  Netapp Hci Compute Node cpe:2.3:h:netapp:hci_compute_node:-

Configuration #4

AND
    CPE23 From Up To
OR  
  Netapp A700s Firmware cpe:2.3:o:netapp:a700s_firmware:-
OR  
  Running on/with
  Netapp A700s cpe:2.3:h:netapp:a700s:-

Configuration #5

AND
    CPE23 From Up To
OR  
  Netapp H300s Firmware cpe:2.3:o:netapp:h300s_firmware:-
OR  
  Running on/with
  Netapp H300s cpe:2.3:h:netapp:h300s:-

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp H500s Firmware cpe:2.3:o:netapp:h500s_firmware:-
OR  
  Running on/with
  Netapp H500s cpe:2.3:h:netapp:h500s:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp H700s Firmware cpe:2.3:o:netapp:h700s_firmware:-
OR  
  Running on/with
  Netapp H700s cpe:2.3:h:netapp:h700s:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp H410s Firmware cpe:2.3:o:netapp:h410s_firmware:-
OR  
  Running on/with
  Netapp H410s cpe:2.3:h:netapp:h410s:-

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H410c Firmware cpe:2.3:o:netapp:h410c_firmware:-
OR  
  Running on/with
  Netapp H410c cpe:2.3:h:netapp:h410c:-

Configuration #10

    CPE23 From Up To
  Oracle Communications Cloud Native Core Binding Support Function 22.1.3 cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3
  Oracle Communications Cloud Native Core Network Exposure Function 22.1.1 cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.1
  Oracle Communications Cloud Native Core Policy 22.2.0 cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.2.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...