PT-2025-17218 · Linux+2 · Linux Kernel+2

Published

2025-04-17

·

Updated

2025-05-21

·

CVE-2021-47669

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use after free bug has been identified in the Linux kernel, specifically in the vxcan xmit function. The issue arises after calling netif rx ni(skb), where dereferencing skb becomes unsafe. This is particularly problematic because the canfd frame cfd, which shares memory with skb, is accessed after the netif rx ni() call.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47669
OPENSUSE-SU-2025_01633-1
SUSE-SU-2025:01600-1
SUSE-SU-2025:01633-1
SUSE-SU-2025:1574-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_01633-1

Affected Products

Astra Linux
Linux Kernel
Suse