cbcvebase.
CVE-2021-47506
published 2024-05-24

CVE-2021-47506: In the Linux kernel, the following vulnerability has been resolved: nfsd: fix use-after-free due to delegation race A delegation break could arrive as soon as…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.7th percentile
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix use-after-free due to delegation race A delegation break could arrive as soon as we've called vfs_setlease. A delegation break runs a callback which immediately (in nfsd4_cb_recall_prepare) adds the delegation to del_recall_lru. If we then exit nfs4_set_delegation without hashing the delegation, it will be freed as soon as the callback is done with it, without ever being removed from del_recall_lru. Symptoms show up later as use-after-free or list corruption warnings, usually in the laundromat thread. I suspect aba2072f4523 "nfsd: grant read delegations to clients holding writes" made this bug easier to hit, but I looked as far back as v3.0 and it looks to me it already had the same problem. So I'm not sure where the bug was introduced; it may have been there from the beginning.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= dff1399f8addf7129c49bb2227469da79cc30b47 < 04a8d07f3d58308b92630045560799a3faa3ebce04a8d07f3d58308b92630045560799a3faa3ebce
linuxlinux>= dff1399f8addf7129c49bb2227469da79cc30b47 < 348714018139c39533c55661a0c7c990671396b4348714018139c39533c55661a0c7c990671396b4
linuxlinux>= dff1399f8addf7129c49bb2227469da79cc30b47 < 33645d3e22720cac1e4548f8fef57bf0649536ee33645d3e22720cac1e4548f8fef57bf0649536ee
linuxlinux>= dff1399f8addf7129c49bb2227469da79cc30b47 < 2becaa990b93cbd2928292c0b669d3abb6cf06d42becaa990b93cbd2928292c0b669d3abb6cf06d4
linuxlinux>= dff1399f8addf7129c49bb2227469da79cc30b47 < e0759696de6851d7536efddfdd2dfed4c4df1f09e0759696de6851d7536efddfdd2dfed4c4df1f09
linuxlinux>= dff1399f8addf7129c49bb2227469da79cc30b47 < eeb0711801f5e19ef654371b627682aed3b11373eeb0711801f5e19ef654371b627682aed3b11373
linuxlinux>= dff1399f8addf7129c49bb2227469da79cc30b47 < 148c816f10fd11df27ca6a9b3238cdd42fa72cd3148c816f10fd11df27ca6a9b3238cdd42fa72cd3
linuxlinux>= dff1399f8addf7129c49bb2227469da79cc30b47 < 548ec0805c399c65ed66c6641be467f717833ab5548ec0805c399c65ed66c6641be467f717833ab5
linuxlinux_kernel< 4.4.2964.4.296
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 4.4.0-278.3124.4.0-278.312
linuxlinux_kernel>= 0 < 4.4.0-268.3024.4.0-268.302
linuxlinux_kernel>= 0 < 4.15.0-247.2594.15.0-247.259
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 0 < 5.15.0-141.1515.15.0-141.151
linuxlinux_kernel>= 0 < 6.8.0-59.616.8.0-59.61
linuxlinux_kernel>= 4.10 < 4.14.2594.14.259
linuxlinux_kernel>= 4.15 < 4.19.2224.19.222
linuxlinux_kernel>= 4.20 < 5.4.1685.4.168

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.