PT-2024-11300 · Linux+1 · Linux Kernel+1

Abaci

·

Published

2021-07-13

·

Updated

2024-12-26

·

CVE-2021-47299

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 5.13.0
Description A use-after-free vulnerability has been identified in the Linux kernel, specifically in the bpf xdp link release function. This issue occurs when the dev get by index and dev xdp attach link functions are called, leading to a situation where the dev xdp uninstall function is invoked, causing the xdp link to not be detached automatically when the device is released. As a result, the link->dev pointer still points to the device, which has already been released, resulting in a use-after-free error.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, versions prior to 5.13.0 are affected, so updating to 5.13.0 or later will mitigate this issue.
Note: The provided input does not specify the exact fixed version, but based on the information given, it is clear that version 5.13.0 is the version where the issue was identified, and thus, updating to this or a later version should resolve the issue.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07389
CVE-2021-47299

Affected Products

Astra Linux
Linux Kernel