CVE-2021-47291
HIGHLinux Kernel - Out-of-bounds Read in fib6_nh_flush_exceptions
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions While running the self-tests on a KASAN enabled kernel, I observed a slab-out-of-bounds splat very similar to the one reported in commit 821bbf79fe46 ("ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions"). We additionally need to take care of fib6_metrics initialization failure when the caller provides an nh. The fix is similar, explicitly free the route instead of calling fib6_info_release on a half-initialized object.
References (4)
Core 4
Core References
Scores
CVSS v3
7.1
EPSS
0.0025
EPSS Percentile
15.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (12)
Linux/Linux
< 5.3
Linux/Linux
5.10.54 - 5.10.*
Linux/Linux
5.13.6 - 5.13.*
Linux/Linux
5.14
Linux/Linux
5.3
Linux/Linux
5.4.136 - 5.4.*
Linux/Linux
f88d8ea67fbdbac7a64bfa6ed9a2ba27bb822f74 - 115784bcccf135c3a3548098153413d76f16aae0
Linux/Linux
f88d8ea67fbdbac7a64bfa6ed9a2ba27bb822f74 - 830251361425c5be044db4d826aaf304ea3d14c6
Linux/Linux
f88d8ea67fbdbac7a64bfa6ed9a2ba27bb822f74 - 8fb4792f091e608a0a1d353dfdf07ef55a719db5
Linux/Linux
f88d8ea67fbdbac7a64bfa6ed9a2ba27bb822f74 - ce8fafb68051fba52546f8bbe8621f7641683680
... and 2 more
Published
May 21, 2024
Tracked Since
Feb 18, 2026