CVE-2021-20265

MEDIUM

Linux Kernel - Use-After-Free in unix_stream_recvmsg

Title source: llm
STIX 2.1

Description

A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.

References (3)

Core 3
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1908827
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401 CWE-400
Status published
Products (2)
linux/linux_kernel
oracle/tekelec_platform_distribution 7.4.0 - 7.7.1
Published Mar 10, 2021
Tracked Since Feb 18, 2026