cbcvebase.
CVE-2021-47538
published 2024-05-24

CVE-2021-47538: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix rxrpc_local leak in rxrpc_lookup_peer() Need to call rxrpc_put_local() for peer…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix rxrpc_local leak in rxrpc_lookup_peer() Need to call rxrpc_put_local() for peer candidate before kfree() as it holds a ref to rxrpc_local. [DH: v2: Changed to abstract the peer freeing code out into a function]

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 4.19.82 < 4.19.2204.19.220
linuxlinux>= 5.3.9 < 5.45.4
linuxlinux>= 9ebeddef58c41bd700419cdcece24cf64ce32276 < 3e70e3a72d80b16094faccbe438cd53761c3503a3e70e3a72d80b16094faccbe438cd53761c3503a
linuxlinux>= 9ebeddef58c41bd700419cdcece24cf64ce32276 < 60f0b9c42cb80833a03ca57c1c8b078d716e71d160f0b9c42cb80833a03ca57c1c8b078d716e71d1
linuxlinux>= 9ebeddef58c41bd700419cdcece24cf64ce32276 < 9469273e616ca8f1b6e3773c5019f21b4c8d828c9469273e616ca8f1b6e3773c5019f21b4c8d828c
linuxlinux>= 9ebeddef58c41bd700419cdcece24cf64ce32276 < beacff50edbd6c9659a6f15fc7f6126909fade29beacff50edbd6c9659a6f15fc7f6126909fade29
linuxlinux>= e8e51ce79c157188e209e5ea0afaf6b42dd76104 < 913c24af2d13a3fd304462916ee98e298d56bdce913c24af2d13a3fd304462916ee98e298d56bdce
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 4.19.82 < 4.19.2204.19.220
linuxlinux_kernel>= 5.11 < 5.15.75.15.7
linuxlinux_kernel>= 5.3.9 < 5.45.4
linuxlinux_kernel>= 5.4.1 < 5.4.1645.4.164
linuxlinux_kernel>= 5.5 < 5.10.845.10.84

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.