CVE-2021-47106
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2021-47106 is a use-after-free vulnerability in the Linux kernel's netfilter module. Specifically, in the functions nft_set_catchall_destroy() and nft_set_destroy(), there is a failure to properly handle list entries, resulting in a use-after-free condition. This issue was reported by syzbot and can lead to a kernel crash and potential system compromise. The vulnerability affects versions prior to 5.16.0-rc5 and was discovered through the syzkaller fuzzing project. To mitigate this vulnerability, users are advised to update their Linux kernel to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX