cbcvebase.
CVE-2021-4028
published 2022-08-24

CVE-2021-4028: A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.12-1 (bookworm)linux 5.14.12-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 5.10 < 5.10.715.10.71
linuxlinux_kernel>= 5.11 < 5.14.105.14.10
paloaltopan-os
suselinux_enterprise

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH