PT-2025-13279 · Linux+3 · Linux Kernel+3
Published
2021-09-06
·
Updated
2025-06-02
·
CVE-2021-4454
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.14.0-rc7+
Description
A vulnerability in the Linux kernel has been resolved, related to the
j1939 session deactivate() function. The issue arises from an incorrect conclusion that j1939 session deactivate() should be called with a session ref-count of at least 2. However, in some concurrent scenarios, j1939 session deactivate can be called with the session ref-count less than 2, leading to a WARN ON ONCE. The problem occurs due to a race condition between j1939 xtp rx eoma and j1939 session deactivate.Recommendations
For Linux kernel versions prior to 5.14.0-rc7+, update to a version that includes the fix for the errant WARN ON ONCE in
j1939 session deactivate(). As a temporary workaround, consider disabling the j1939 session deactivate() function until a patch is available. Restrict access to the j1939 module to minimize the risk of exploitation. Avoid using the j1939 session deactivate() function in concurrent scenarios until the issue is resolved.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse