Vulnerabilities > CVE-2021-41073 - Release of Invalid Pointer or Reference vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.

Vulnerable Configurations

Part Description Count
OS
Linux
176
OS
Debian
1
OS
Fedoraproject
2
OS
Netapp
8
Application
Netapp
2
Hardware
Netapp
8

Common Weakness Enumeration (CWE)