PT-2024-9081 · Linux+3 · Linux Kernel+3

Published

2024-05-24

·

Updated

2024-11-26

·

CVE-2021-47539

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to a leak in the rxrpc look up bundle() function, where a reference to rxrpc peer is held. This leak can potentially allow an attacker to access confidential information. The problem arises because rxrpc put peer() is not called for the bundle candidate before kfree(), resulting in the leak.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10763
CVE-2021-47539
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2939-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse