CVE-2021-47106

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 4, 2024
Updated: Jan 14, 2025
CWE ID 416

Summary

CVE-2021-47106 is a use-after-free vulnerability in the Linux kernel's netfilter module. Specifically, in the functions nft_set_catchall_destroy() and nft_set_destroy(), there is a failure to properly handle list entries, resulting in a use-after-free condition. This issue was reported by syzbot and can lead to a kernel crash and potential system compromise. The vulnerability affects versions prior to 5.16.0-rc5 and was discovered through the syzkaller fuzzing project. To mitigate this vulnerability, users are advised to update their Linux kernel to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share