CVE-2021-46923

MEDIUM

Linux Kernel 5.12-5.15.12 - Resource Exposure via mount_setattr Reference Leak

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: fs/mount_setattr: always cleanup mount_kattr Make sure that finish_mount_kattr() is called after mount_kattr was succesfully built in both the success and failure case to prevent leaking any references we took when we built it. We returned early if path lookup failed thereby risking to leak an additional reference we took when building mount_kattr when an idmapped mount was requested.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (7)
Linux/Linux < 5.12
Linux/Linux 5.12
Linux/Linux 5.15.13 - 5.15.*
Linux/Linux 5.16
Linux/Linux 9caccd41541a6f7d6279928d9f971f6642c361af - 012e332286e2bb9f6ac77d195f17e74b2963d663
Linux/Linux 9caccd41541a6f7d6279928d9f971f6642c361af - 47b5d0a7532d39e42a938f81e3904268145c341d
linux/linux_kernel 5.12.0 - 5.15.13
Published Feb 27, 2024
Tracked Since Feb 18, 2026