544
VMScore

CVE-2021-20226

Published: 23/02/2021 Updated: 28/07/2023
CVSS v2 Base Score: 6.1 | Impact Score: 8.5 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 544
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:C

Vulnerability Summary

A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to performing operations on the object by not incrementing the file reference counter while in use. The highest threat from this vulnerability is to data integrity, confidentiality and system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

netapp cloud backup -

Vendor Advisories

An inappropriate handling of descriptors that results in a use-after-free vulnerability was found on the Linux kernel before version 510 ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: CVE-2021-20226 kernel: use-after-free in io_uring feature <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Ale ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2021-20226 kernel: use-after-free in io_uring feature <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Rohit K ...