PT-2024-11375 · Linux+3 · Linux Kernel+3
Li Jinlin
·
Published
2021-09-15
·
Updated
2025-07-08
·
CVE-2021-47379
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 4.18.0-147
Description
A use-after-free vulnerability has been resolved in the Linux kernel. The issue occurred in the blk-cgroup component, where a use-after-free report was generated by KASAN during a fuzz test. The vulnerability was caused by the lack of a blkcg lock when destroying a blkg pd. The affected function is
bfq io set weight legacy+0xd3/0x160.Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, update to a version later than 4.18.0-147.
Note: The provided information does not include details about the fixed version or specific patch, so a general recommendation to update the kernel is given.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse
Ubuntu