PT-2021-8078 · Linux+3 · Linux Kernel+3

Yuwen Ng

·

Published

2021-12-21

·

Updated

2024-08-19

·

CVE-2021-46930

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is caused by the uninitialization of list head in the mtu3 component of the Linux kernel. This can lead to a use-after-free error in the list del entry valid function. The call trace includes functions such as dump backtrace, show stack, dump stack, print address description, kasan report, kasan report, and asan load8. The vulnerability is related to the mtu3 req complete and mtu3 gadget stop functions. There is no information about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06316
CVE-2021-46930
OPENSUSE-SU-2024_1321-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1489-1
OPENSUSE-SU-2024_1490-1
SUSE-SU-2024:1320-1
SUSE-SU-2024:1321-1
SUSE-SU-2024:1454-1
SUSE-SU-2024:1465-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1489-1
SUSE-SU-2024:1490-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse