CVE-2021-46283
MEDIUMLinux Kernel < 5.12.13 - Denial of Service via Uninitialized nft_set_elem_expr_alloc
Title source: llmDescription
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
References (3)
Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.13
Patch, Vendor Advisory x_refsource_misc
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ad9f151e560b016b6ad3280b48e42fa11e1a5440
Third Party Advisory x_refsource_misc
https://syzkaller.appspot.com/bug?id=22c3987f75a7b90e238a26b5a5920525c2d1f345
Scores
CVSS v3
5.5
EPSS
0.0032
EPSS Percentile
23.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-665
Status
published
Products (1)
linux/linux_kernel
< 5.12.13
Published
Jan 11, 2022
Tracked Since
Feb 18, 2026