cbcvebase.
CVE-2021-47248
published 2024-05-21

CVE-2021-47248: In the Linux kernel, the following vulnerability has been resolved: udp: fix race between close() and udp_abort() Kaustubh reported and diagnosed a panic in…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved: udp: fix race between close() and udp_abort() Kaustubh reported and diagnosed a panic in udp_lib_lookup(). The root cause is udp_abort() racing with close(). Both racing functions acquire the socket lock, but udp{v6}_destroy_sock() release it before performing destructive actions. We can't easily extend the socket lock scope to avoid the race, instead use the SOCK_DEAD flag to prevent udp_abort from doing any action when the critical race happens. Diagnosed-and-tested-by: Kaustubh Pandey

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.46-1 (bookworm)linux 5.10.46-1 (bookworm)
linuxlinux
linuxlinux>= 5d77dca82839ef016a93ad7acd7058b14d967752 < e3c36c773aed0fef8b1d3d555b43393ec564400fe3c36c773aed0fef8b1d3d555b43393ec564400f
linuxlinux>= 5d77dca82839ef016a93ad7acd7058b14d967752 < a0882f68f54f7a8b6308261acee9bd4faab5a69ea0882f68f54f7a8b6308261acee9bd4faab5a69e
linuxlinux>= 5d77dca82839ef016a93ad7acd7058b14d967752 < 2f73448041bd0682d4b552cfd314ace66107f1ad2f73448041bd0682d4b552cfd314ace66107f1ad
linuxlinux>= 5d77dca82839ef016a93ad7acd7058b14d967752 < 5a88477c1c85e4baa51e91f2d40f2166235daa565a88477c1c85e4baa51e91f2d40f2166235daa56
linuxlinux>= 5d77dca82839ef016a93ad7acd7058b14d967752 < 8729ec8a2238152a4afc212a331a6cd2c61aeeac8729ec8a2238152a4afc212a331a6cd2c61aeeac
linuxlinux>= 5d77dca82839ef016a93ad7acd7058b14d967752 < 65310b0aff86980a011c7c7bfa487a333d4ca24165310b0aff86980a011c7c7bfa487a333d4ca241
linuxlinux>= 5d77dca82839ef016a93ad7acd7058b14d967752 < a8b897c7bcd47f4147d066e22cc01d1026d7640ea8b897c7bcd47f4147d066e22cc01d1026d7640e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 4.10 < 4.14.2384.14.238
linuxlinux_kernel>= 4.15 < 4.19.1964.19.196
linuxlinux_kernel>= 4.20 < 5.4.1285.4.128
linuxlinux_kernel>= 4.9 < 4.9.2744.9.274
linuxlinux_kernel>= 5.11 < 5.12.135.12.13
linuxlinux_kernel>= 5.5 < 5.10.465.10.46

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.