PT-2024-11155 · Linux+2 · Linux Kernel+2

Syzbot

·

Published

2021-05-11

·

Updated

2024-11-01

·

CVE-2021-47078

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.12.0-syzkaller
Description The issue is related to the RDMA/rxe component of the Linux kernel. Specifically, the rxe qp do cleanup() function relies on valid pointer values in the QP (Queue Pair) for properly created ones. However, if rxe qp from init() fails, it fills the QP with garbage, leading to a refcount t underflow and use-after-free error. This vulnerability can cause a system crash or potentially allow an attacker to execute arbitrary code.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Ensure that all systems using the affected kernel versions are updated as soon as possible to prevent potential exploitation. Additionally, consider implementing security measures such as memory protection and access control to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07274
CVE-2021-47078
OESA-2024-1483
OESA-2024-1484
OPENSUSE-SU-2024_0857-1
SUSE-SU-2024:0856-1
SUSE-SU-2024:0857-1
SUSE-SU-2024:0925-1
SUSE-SU-2024:0926-1
SUSE-SU-2024:0975-1
SUSE-SU-2024:0976-1

Affected Products

Astra Linux
Linux Kernel
Suse