PT-2021-8259 · Linux+1 · Linux Kernel+1

Pablo Neira Ayuso

·

Published

2021-05-27

·

Updated

2024-11-07

·

CVE-2021-47129

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The vulnerability is related to the nft ct expect obj eval() function in the Linux kernel's netfilter component. It is caused by the function calling nf ct ext add() for a confirmed conntrack entry, although nf ct ext add() can only be called for unconfirmed conntrack entries. This can lead to a denial of service. The issue can be mitigated by adding a new action to attach a generic ct helper to the first packet and using this ct helper extension from follow-up packets to create the ct expectation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-00797
CVE-2021-47129

Affected Products

Astra Linux
Linux Kernel