Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-4150

Опубликовано: 23 мар. 2022
Источник: nvd
CVSS3: 5.5
CVSS2: 4.9
EPSS Низкий

Описание

A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 5.15 (исключая)
cpe:2.3:o:linux:linux_kernel:5.15:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc6:*:*:*:*:*:*

EPSS

Процентиль: 13%
0.00043
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-416
CWE-416

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk.

CVSS3: 5.1
redhat
больше 4 лет назад

A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk.

CVSS3: 5.5
msrc
почти 4 года назад

A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk.

CVSS3: 5.5
debian
почти 4 года назад

A use-after-free flaw was found in the add_partition in block/partitio ...

CVSS3: 5.5
github
почти 4 года назад

A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk.

EPSS

Процентиль: 13%
0.00043
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-416
CWE-416