PT-2021-5993 · Linux+3 · Linux Kernel+3

Syzbot

·

Published

2021-06-04

·

Updated

2023-05-17

·

CVE-2021-46283

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.12.13
Description The issue is related to the nf tables newset function in the Linux kernel, which allows local users to cause a denial of service due to a missing initialization for nft set elem expr alloc. This can lead to a NULL pointer dereference and general protection fault. A local user can exploit this by setting a netfilter table expression in their own namespace.
Recommendations For Linux kernel versions prior to 5.12.13, update to version 5.12.13 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

DoS

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2050
ALT-PU-2021-2199
ALT-PU-2021-2315
ALT-PU-2021-2326
ALT-PU-2021-2330
ALT-PU-2021-3481
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
BDU:2022-00513
CVE-2021-46283
OPENSUSE-SU-2022:0169-1
OPENSUSE-SU-2022:0198-1
OPENSUSE-SU-2022_0169-1
OPENSUSE-SU-2022_0198-1
SUSE-SU-2022:0169-1
SUSE-SU-2022:0198-1
SUSE-SU-2022:0288-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Suse