PT-2024-11327 · Linux+2 · Linux Kernel+2
Published
2021-06-01
·
Updated
2024-12-26
·
CVE-2021-47328
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a use-after-free vulnerability in the Linux kernel's iSCSI subsystem. If a unbind target call has not been made, there is a potential race condition where
iscsi conn teardown wakes up the EH thread and frees the connection while other threads are still accessing it. To resolve this, the TMF fields are moved from the connection to the session, allowing the iscsi session teardown call to remove the target and its devices, ensuring no further access to the session.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse