PT-2024-9081 · Linux+3 · Linux Kernel+3
Published
2024-05-24
·
Updated
2024-11-26
·
CVE-2021-47539
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue is related to a leak in the
rxrpc look up bundle() function, where a reference to rxrpc peer is held. This leak can potentially allow an attacker to access confidential information. The problem arises because rxrpc put peer() is not called for the bundle candidate before kfree(), resulting in the leak.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse