CVE-2021-4028

Updated: 2023-11-04 20:52:33.980511

Description:

A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated
AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Needs Triage 2023-11-07 16:11:15
AlmaLinux 9.2 FIPS kernel 5.14.0 7.8 HIGH Needs Triage 2023-11-20 10:06:42
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2023-11-09 13:19:40
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2023-11-03 14:07:33
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2023:1686585068 2023-06-13 09:10:11
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2023:1686651204 2023-06-13 09:10:11
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2023-09-15 14:14:16
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2023-11-09 13:19:40
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2023:1684277390 2023-05-16 21:24:14
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Not Vulnerable 2022-10-05 03:15:02