PT-2024-11375 · Linux+3 · Linux Kernel+3

Li Jinlin

·

Published

2021-09-15

·

Updated

2025-07-08

·

CVE-2021-47379

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.18.0-147
Description A use-after-free vulnerability has been resolved in the Linux kernel. The issue occurred in the blk-cgroup component, where a use-after-free report was generated by KASAN during a fuzz test. The vulnerability was caused by the lack of a blkcg lock when destroying a blkg pd. The affected function is bfq io set weight legacy+0xd3/0x160.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, update to a version later than 4.18.0-147.
Note: The provided information does not include details about the fixed version or specific patch, so a general recommendation to update the kernel is given.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04682
CVE-2021-47379
OPENSUSE-SU-2024_2189-1
OPENSUSE-SU-2024_2362-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2362-1
SUSE-SU-2024:2365-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2384-1
SUSE-SU-2024:2561-1
USN-7627-1
USN-7627-2

Affected Products

Astra Linux
Linux Kernel
Suse
Ubuntu