cbcvebase.
CVE-2021-47086
published 2024-03-04

CVE-2021-47086: In the Linux kernel, the following vulnerability has been resolved: phonet/pep: refuse to enable an unbound pipe This ioctl() implicitly assumed that the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: phonet/pep: refuse to enable an unbound pipe This ioctl() implicitly assumed that the socket was already bound to a valid local socket name, i.e. Phonet object. If the socket was not bound, two separate problems would occur: 1) We'd send an pipe enablement request with an invalid source object. 2) Later socket calls could BUG on the socket unexpectedly being connected yet not bound to a valid object.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= bdb6e697b2a76c541960b86ab8fda88f3de1adf2 < 0bbdd62ce9d44f3a22059b3d20a0df977d9f6d590bbdd62ce9d44f3a22059b3d20a0df977d9f6d59
linuxlinux>= bdb6e697b2a76c541960b86ab8fda88f3de1adf2 < b10c7d745615a092a50c2e03ce70446d2bec2acab10c7d745615a092a50c2e03ce70446d2bec2aca
linuxlinux>= bdb6e697b2a76c541960b86ab8fda88f3de1adf2 < 311601f114859d586d5ef8833d60d3aa23282161311601f114859d586d5ef8833d60d3aa23282161
linuxlinux>= bdb6e697b2a76c541960b86ab8fda88f3de1adf2 < 982b6ba1ce626ef87e5c29f26f2401897554f235982b6ba1ce626ef87e5c29f26f2401897554f235
linuxlinux>= bdb6e697b2a76c541960b86ab8fda88f3de1adf2 < 48c76fc53582e7f13c1e0b11c916e503256c4d0b48c76fc53582e7f13c1e0b11c916e503256c4d0b
linuxlinux>= bdb6e697b2a76c541960b86ab8fda88f3de1adf2 < 52ad5da8e316fa11e3a50b3f089aa63e4089bf5252ad5da8e316fa11e3a50b3f089aa63e4089bf52
linuxlinux>= bdb6e697b2a76c541960b86ab8fda88f3de1adf2 < 53ccdc73eedaf0e922c45b569b797d2796fbaafa53ccdc73eedaf0e922c45b569b797d2796fbaafa
linuxlinux>= bdb6e697b2a76c541960b86ab8fda88f3de1adf2 < 75a2f31520095600f650597c0ac41f48b5ba006875a2f31520095600f650597c0ac41f48b5ba0068
linuxlinux_kernel< 4.4.2974.4.297
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 4.4.0-262.2964.4.0-262.296
linuxlinux_kernel>= 4.10 < 4.14.2604.14.260
linuxlinux_kernel>= 4.15 < 4.19.2234.19.223
linuxlinux_kernel>= 4.20 < 5.4.1695.4.169
linuxlinux_kernel>= 4.5 < 4.9.2954.9.295
linuxlinux_kernel>= 5.11 < 5.15.125.15.12
linuxlinux_kernel>= 5.5 < 5.10.895.10.89

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.