cbcvebase.
CVE-2021-4203
published 2022-03-25

CVE-2021-4203: A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the…

medium6.8CVSS 3.1
AVNACHPRLUINSUCHINAH
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.12-1 (bookworm)linux 5.14.12-1 (bookworm)
linuxlinux_kernel< 5.155.15
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 4.4.0-239.2734.4.0-239.273
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.10.111.1-1_on_cbl_mariner_1.0
netappe-series_santricity_os_controller11.0.0 – 11.70.2
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_network_exposure_function
oraclecommunications_cloud_native_core_policy

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
osv6.8MEDIUM