#VU63422 Use-after-free


Published: 2022-05-19

Vulnerability identifier: #VU63422

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2021-45868

CWE-ID: CWE-416

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial-of-service attack.

The vulnerability exists due to fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). A local user can trigger use-after-free error and perform a denial-of-service attack.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Linux kernel: 5.15.0 - 5.15.2


CPE

External links
http://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.3
http://www.openwall.com/lists/oss-security/2022/03/17/2
http://www.openwall.com/lists/oss-security/2022/03/17/1
http://bugzilla.kernel.org/show_bug.cgi?id=214655
http://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9bf3d20331295b1ecb81f4ed9ef358c51699a050
http://security.netapp.com/advisory/ntap-20220419-0003/


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability