PT-2024-11390 · Linux+2 · Linux Kernel+2

Syzbot

·

Published

2021-09-21

·

Updated

2024-06-25

·

CVE-2021-47394

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue has been identified in the Linux kernel's netfilter nf tables component. The problem arises because all get operations are lockless, allowing a parallel GET request to access the table object even after it has been deleted. This issue can be exploited due to the commit mutex held by nft rcv nl event() not being sufficient to prevent read-accesses to the table object after synchronize rcu(). The estimated number of potentially affected devices and details about real-world incidents are not provided. Technical details about exploitation include the nft table lookup function and the nf tables getset function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07503
CVE-2021-47394
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Linux Kernel
Suse