Review reviewHigh

CVE-2021-47506

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix use-after-free due to delegation race A delegation break could arrive as soon as we've called vfs_setlease. A delegation break runs a callback which immediately (in nfsd4_cb_recall_prepare) adds the delegation to del_recall_lru. If we then exit nfs4_set_delegation without hashing the delegation, it will be freed as soon as the callback is done with it, without ever being removed from del_recall_lru. Symptoms show up later as use-after-free or list corruption warnings, usually in the laundromat thread. I suspect ab...

CVSS
7.8
EPSS
0.78%
52.5% percentile
CISA KEV
Not listed
Published
2024.05.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.78%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix use-after-free due to delegation race A delegation break could arrive as soon as we've called vfs_setlease. A delegation break runs a callback which immediately (in nfsd4_cb_recall_prepare) adds the delegation to del_recall_lru. If we then exit nfs4_set_delegation without hashing the delegation, it will be freed as soon as the callback is done with it, without ever being removed from del_recall_lru. Symptoms show up later as use-after-free or list corruption warnings, usually in the laundromat thread. I suspect ab...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= dff1399f8addf7129c49bb2227469da79cc30b47 < 04a8d07f3d58308b92630045560799a3faa3ebce, >= dff1399f8addf7129c49bb2227469da79cc30b47 < 348714018139c39533c55661a0c7c990671396b4, >= dff1399f8addf7129c49bb2227469da79cc30b47 < 33645d3e22720cac1e4548f8fef57bf0649536ee, >= dff1399f8addf7129c49bb2227469da79cc30b47 < 2becaa990b93cbd2928292c0b669d3abb6cf06d4, >= dff1399f8addf7129c49bb2227469da79cc30b47 < e0759696de6851d7536efddfdd2dfed4c4df1f09, >= dff1399f8addf7129c49bb2227469da79cc30b47 < eeb0711801f5e19ef654371b627682aed3b11373, >= dff1399f8addf7129c49bb2227469da79cc30b47 < 148c816f10fd11df27ca6a9b3238cdd42fa72cd3, >= dff1399f8addf7129c49bb2227469da79cc30b47 < 548ec0805c399c65ed66c6641be467f717833ab5, >= 3.17, < 4.4.296, >= 4.5 < 4.9.294, >= 4.10 < 4.14.259, >= 4.15 < 4.19.222, >= 4.20 < 5.4.168, >= 5.5 < 5.10.85, >= 5.11 < 5.15.8, 5.15
Fixed versions
4.4.296, 4.9.294, 4.14.259, 4.19.222, 5.4.168, 5.10.85, 5.15.8

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2021-47506 — Linux Linux, linux kernel | SECUFOCUS NOW