CVE-2021-47141
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2021-47141 is a Linux kernel vulnerability that has been addressed. The issue lies in the gve driver's handling of interrupt notifications. Specifically, when freeing notification blocks, the kernel fails to check for NULL pointers in the priv->msix_vectors index. If the allocation of priv->msix_vectors fails, this could result in a NULL pointer dereference upon driver unloading. This vulnerability could potentially be exploited to cause a denial of service or gain unauthorized access. The Linux kernel community has released patches to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX