A flaw in the Linux kernel's implementation of RDMA communications...
Vulnerability Description
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4028
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lkml.org/lkml/2021/10/4/697
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=bc0bdc5afaa74
- https://bugzilla.redhat.com/show_bug.cgi?id=2027201
- https://access.redhat.com/security/cve/CVE-2021-4028
- https://bugzilla.suse.com/show_bug.cgi?id=1193167#c0
- https://security.netapp.com/advisory/ntap-20221228-0002/