#VU90086 Use-after-free in Linux kernel - CVE-2021-47254
Published: May 31, 2024 / Updated: May 14, 2025
Vulnerability identifier: #VU90086
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-47254
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the __acquires() and gfs2_scan_glock_lru() functions in fs/gfs2/glock.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
External links
- https://git.kernel.org/stable/c/38ce329534500bf4ae71f81df6a37a406cf187b4
- https://git.kernel.org/stable/c/92869945cc5b78ee8a1ef90336fe070893e3458a
- https://git.kernel.org/stable/c/0364742decb0f02bc183404868b82896f7992595
- https://git.kernel.org/stable/c/094bf5670e762afa243d2c41a5c4ab71c7447bf4
- https://git.kernel.org/stable/c/86fd5b27db743a0ce0cc245e3a34813b2aa6ec1d
- https://git.kernel.org/stable/c/a61156314b66456ab6a291ed5deba1ebd002ab3c
- https://git.kernel.org/stable/c/e87ef30fe73e7e10d2c85bdcc778dcec24dca553
- https://git.kernel.org/stable/c/1ab19c5de4c537ec0d9b21020395a5b5a6c059b2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.238
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.196
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.274
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.274
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.45
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.127