Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix use-after-free in nfs4_init_client() KASAN reports a use-after-free when attempting to mount two different exports through two different NICs that belong to the same server. Olga was able to hit this with kernels starting somewhere between 5.7 and 5.10, but I traced the patch that introduced the clear_bit() call to 4.13. So something must have changed in the refcounting of the clp pointer to make this call to nfs_put_client() the very last one.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.13, < 4.14.237 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/3e3c7ebbfac152d08be75c92802a64a1f6471a15Patch
- https://git.kernel.org/stable/c/42c10b0db064e45f5c5ae7019bbf2168ffab766cPatch
- https://git.kernel.org/stable/c/476bdb04c501fc64bf3b8464ffddefc8dbe01577Patch
- https://git.kernel.org/stable/c/72651c6579a25317a90536181d311c663d0329abPatch
- https://git.kernel.org/stable/c/c3b6cf64dfe4ef96e7341508d50d6998da7062c7Patch
- https://git.kernel.org/stable/c/c7eab9e2d7b4e983ce280276fb920af649955897Patch
- https://git.kernel.org/stable/c/3e3c7ebbfac152d08be75c92802a64a1f6471a15Patch
- https://git.kernel.org/stable/c/42c10b0db064e45f5c5ae7019bbf2168ffab766cPatch
- https://git.kernel.org/stable/c/476bdb04c501fc64bf3b8464ffddefc8dbe01577Patch
- https://git.kernel.org/stable/c/72651c6579a25317a90536181d311c663d0329abPatch
- https://git.kernel.org/stable/c/c3b6cf64dfe4ef96e7341508d50d6998da7062c7Patch
- https://git.kernel.org/stable/c/c7eab9e2d7b4e983ce280276fb920af649955897Patch
FAQ
What is CVE-2021-47259?
CVE-2021-47259 is a vulnerability with a CVSS score of 7.5 (HIGH). In the Linux kernel, the following vulnerability has been resolved: NFS: Fix use-after-free in nfs4_init_client() KASAN reports a use-after-free when attempting to mount two different exports throug...
How severe is CVE-2021-47259?
CVE-2021-47259 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47259?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.