CVE-2021-4028: Use After Free
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.
Other sources
A flaw in the Linux kernels implementation of RDMA communications manager listener code allowed an attacker with local access to setup socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:1199
- RHSA-2022:1185
- RHSA-2022:1198
- RHSA-2022:2189
- RHSA-2022:2188
- RHSA-2022:2186
- RHSA-2022:2211
- RHSA-2022:1324
- RHSA-2022:1373
- RHSA-2022:1555
- RHSA-2022:1535
- RHSA-2022:1550
- RHSA-2022:0823
- RHSA-2022:0851
- RHSA-2022:0958
- RHSA-2022:0629
- RHSA-2022:0590
- RHSA-2022:0636
- RHSA-2022:0771
- RHSA-2022:0772
- RHSA-2022:0777
- RHSA-2022:1263
- RHSA-2022:4896
Frequently Asked Questions
What is CVE-2021-4028?
CVE-2021-4028 is a vulnerability in the Linux kernel's implementation of RDMA communications manager listener code.
How severe is CVE-2021-4028?
CVE-2021-4028 has a severity value of 7, which is considered high.
What is the affected software for CVE-2021-4028?
The affected software includes Red Hat kernel versions up to 5.15, kernel-rt versions up to 3.10.0-1160.62.1.rt56.1203.el7, and SUSE Linux Enterprise versions 15.0-sp3 and 15.0-sp4.
How do I fix CVE-2021-4028?
To fix CVE-2021-4028, you need to update your Linux kernel to a version that includes the necessary patches. Refer to the vendor's security advisory for the specific kernel versions that address the vulnerability.
Where can I find more information about CVE-2021-4028?
You can find more information about CVE-2021-4028 in the Red Hat bugzilla and SUSE bugzilla links provided, as well as the Red Hat security advisory.