4.7
CVE-2021-47461
- EPSS 0.17%
- Veröffentlicht 22.05.2024 07:15:11
- Zuletzt bearbeitet 04.08.2026 10:17:04
- Erkennungen
userfaultfd: fix a race between writeprotect and exit_mmap()
In the Linux kernel, the following vulnerability has been resolved: userfaultfd: fix a race between writeprotect and exit_mmap() A race is possible when a process exits, its VMAs are removed by exit_mmap() and at the same time userfaultfd_writeprotect() is called. The race was detected by KASAN on a development kernel, but it appears to be possible on vanilla kernels as well. Use mmget_not_zero() to prevent the race as done in other userfaultfd operations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.7 < 5.10.76
Linux ≫ Linux Kernel Version >= 5.11 < 5.14.15
Linux ≫ Linux Kernel Version 5.15 Update rc1
Linux ≫ Linux Kernel Version 5.15 Update rc2
Linux ≫ Linux Kernel Version 5.15 Update rc3
Linux ≫ Linux Kernel Version 5.15 Update rc4
Linux ≫ Linux Kernel Version 5.15 Update rc5
Linux ≫ Linux Kernel Version 5.15 Update rc6
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.069 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.7 | 1 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
https://git.kernel.org/stable/c/149958ecd0627a9f1e9c678c25c665400054cd6a
https://git.kernel.org/stable/c/3cda4bfffd4f755645577aaa9e96a606657b4525
https://git.kernel.org/stable/c/cb185d5f1ebf900f4ae3bf84cee212e6dd035aca