PT-2024-11155 · Linux+2 · Linux Kernel+2
Syzbot
·
Published
2021-05-11
·
Updated
2024-11-01
·
CVE-2021-47078
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.12.0-syzkaller
Description
The issue is related to the RDMA/rxe component of the Linux kernel. Specifically, the
rxe qp do cleanup() function relies on valid pointer values in the QP (Queue Pair) for properly created ones. However, if rxe qp from init() fails, it fills the QP with garbage, leading to a refcount t underflow and use-after-free error. This vulnerability can cause a system crash or potentially allow an attacker to execute arbitrary code.Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Ensure that all systems using the affected kernel versions are updated as soon as possible to prevent potential exploitation. Additionally, consider implementing security measures such as memory protection and access control to minimize the risk of exploitation.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse