CVE-2021-28691High· 7.8▾ TwilightGuest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sen…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 26.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.
solidfire_baseboard_management_controllerlinux_kernel >= 5.5.0, < 5.10.43cloud_backuph410c_firmwareh300s_firmwareh500s_firmwareh700s_firmwareh300e_firmwareh500e_firmwareh700e_firmwareh410s_firmwareUpgrade past the affected range:
linux_kernel 5.10.43Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1086High· 7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
CVE-2021-23134High· 7.8Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges
CVE-2022-1199High· 7.5A flaw was found in the Linux kernel
CVE-2022-4696High· 7.8There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation
CVE-2021-40490High· 7.0A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
CVE-2021-3483High· 7.8A flaw was found in the Nosy driver in the Linux kernel