CVE-2021-47417

MEDIUM

Linux Kernel 5.13-5.14.12 - Use-After-Free in libbpf strset

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: libbpf: Fix memory leak in strset Free struct strset itself, not just its internal parts.

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 9.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (8)
Linux/Linux < 5.13
Linux/Linux 5.13
Linux/Linux 5.14.12 - 5.14.*
Linux/Linux 5.15
Linux/Linux 90d76d3ececc74bf43b2a97f178dadfa1e52be54 - 9e8e7504e09831c469b67d6dc11d9a72654bdb8c
Linux/Linux 90d76d3ececc74bf43b2a97f178dadfa1e52be54 - b0e875bac0fab3e7a7431c2eee36a8ccc0c712ac
linux/linux_kernel 5.15 rc1 (4 CPE variants)
linux/linux_kernel 5.13 - 5.14.12
Published May 21, 2024
Tracked Since Feb 18, 2026