PT-2021-26354 · Linux · Linux Kernel
Published
2021-10-28
·
Updated
2021-10-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
Linux Kernel versions prior to v5.14.15
Description:
The issue is related to a use-after-free (UAF) bug in the
j1939 netdev start() function, specifically affecting the rx kref of j1939 priv. The actual impact and attack plausibility have not been proven yet.Recommendations:
For Linux Kernel versions prior to v5.14.15, update to version v5.14.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the
j1939 netdev start() function until a patch is available. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel