CVE-2021-47302 is a use-after-free vulnerability in the Linux kernel's igc network driver. It occurs when the next descriptor to watch is not properly cleared during a TX ring cleanup, leading to invalid memory accesses if igc_poll() runs during a controller reset. This can cause the driver to attempt to free an already freed skb. The vulnerability has a CVSSv3.1 score of 7.8 (High), indicating a local attack vector with low attack complexity, requiring low privileges, and potentially leading to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are there any publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.20, < 5.4.136CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.54CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.13.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.14:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.