Wind River Support Network

HomeDefectsLIN1021-2425
Fixed

LIN1021-2425 : Security Advisory - linux - CVE-2021-46283

Created: Jan 11, 2022    Updated: Jan 23, 2022
Resolved Date: Jan 12, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.6
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.

CREATE(Triage):(User=admin) CVE-2021-46283 (https://nvd.nist.gov/vuln/detail/CVE-2021-46283)

CVEs


Live chat
Online