CVE-2021-46283
published 2022-01-11CVE-2021-46283: nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
24.0th percentile
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux_kernel | < 5.12.13 | 5.12.13 |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| msrc | cm1_kernel_5.10.93.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: DoS in nf_tables_newset in net/netfilter/nf_tables_api.c
vendor_redhat·2022-01-12·CVSS 5.5
CVE-2021-46283 [MEDIUM] CWE-476 kernel: DoS in nf_tables_newset in net/netfilter/nf_tables_api.c
kernel: DoS in nf_tables_newset in net/netfilter/nf_tables_api.c
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
A NULL pointer dereference flaw in the Linux kernel's netfilter subsystem was found in the way user set a netfilter table expression. A local user could use this flaw to crash the system.
Statement: There was no shipped kernel version that was seen affected by this problem. These files are not built in our source code.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Re
Microsoft
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of
vendor_msrc·2022-01-11·CVSS 5.5
CVE-2021-46283 [MEDIUM] CWE-665 nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF
Debian
CVE-2021-46283: linux - nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.1...
vendor_debian·2021·CVSS 5.5
CVE-2021-46283 [MEDIUM] CVE-2021-46283: linux - nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.1...
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
GHSA
GHSA-pc6g-g5m7-f2gr: nf_tables_newset in net/netfilter/nf_tables_api
ghsa_unreviewed·2022-01-12
CVE-2021-46283 [MEDIUM] CWE-665 GHSA-pc6g-g5m7-f2gr: nf_tables_newset in net/netfilter/nf_tables_api
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
OSV
CVE-2021-46283: nf_tables_newset in net/netfilter/nf_tables_api
osv·2022-01-11·CVSS 5.5
CVE-2021-46283 [MEDIUM] CVE-2021-46283: nf_tables_newset in net/netfilter/nf_tables_api
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.13https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ad9f151e560b016b6ad3280b48e42fa11e1a5440https://syzkaller.appspot.com/bug?id=22c3987f75a7b90e238a26b5a5920525c2d1f345https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.13https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ad9f151e560b016b6ad3280b48e42fa11e1a5440https://syzkaller.appspot.com/bug?id=22c3987f75a7b90e238a26b5a5920525c2d1f345
2022-01-11
Published