PT-2024-11327 · Linux+2 · Linux Kernel+2

Published

2021-06-01

·

Updated

2024-12-26

·

CVE-2021-47328

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the Linux kernel's iSCSI subsystem. If a unbind target call has not been made, there is a potential race condition where iscsi conn teardown wakes up the EH thread and frees the connection while other threads are still accessing it. To resolve this, the TMF fields are moved from the connection to the session, allowing the iscsi session teardown call to remove the target and its devices, ensuring no further access to the session.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07327
CVE-2021-47328
OPENSUSE-SU-2024_2362-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2362-1
SUSE-SU-2024:2365-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2384-1
SUSE-SU-2024:2561-1

Affected Products

Astra Linux
Linux Kernel
Suse