CVE-2021-47634 is a use-after-free vulnerability in the Linux kernel's UBI (Unsorted Block Images) subsystem, specifically affecting the ubi_attach and ubi_cdev_ioctl functions. This flaw arises from a race condition between ctrl_cdev_ioctl and ubi_cdev_ioctl due to concurrent lock usage, leading to improper memory management during volume creation and removal. The vulnerability impacts Linux kernel versions and has a CVSS score of 7.8 (High), indicating that a local attacker with low privileges could achieve high confidentiality, integrity, and availability impacts. There is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.84, < 3.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.10.103, < 3.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.12.63, < 3.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.14.77, < 3.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.16.39, < 3.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.