cbcvebase.
CVE-2021-47470
published 2024-05-22

CVE-2021-47470: In the Linux kernel, the following vulnerability has been resolved: mm, slub: fix potential use-after-free in slab_debugfs_fops When sysfs_slab_add failed, we…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: mm, slub: fix potential use-after-free in slab_debugfs_fops When sysfs_slab_add failed, we shouldn't call debugfs_slab_add() for s because s will be freed soon. And slab_debugfs_fops will use s later leading to a use-after-free.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.16-1 (bookworm)linux 5.14.16-1 (bookworm)
linuxlinux
linuxlinux>= 64dd68497be76ab4e237cca06f5324e220d0f050 < 159d8cfbd0428d487c53be4722f33cdab0d25d83159d8cfbd0428d487c53be4722f33cdab0d25d83
linuxlinux>= 64dd68497be76ab4e237cca06f5324e220d0f050 < 67823a544414def2a36c212abadb55b23bcda00c67823a544414def2a36c212abadb55b23bcda00c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 5.14 < 5.14.155.14.15

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.