High severity7.8NVD Advisory· Published Aug 24, 2022· Updated Jun 17, 2026
CVE-2021-4028
CVE-2021-4028
Description
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- Linux kernel/RDMA communications manager listener codedescription
- osv-coords9 versionspkg:rpm/almalinux/kernel-tools-libs-develpkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_5&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3pkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_4&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3pkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_2&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3pkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_7&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3pkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_0&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3pkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_1&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3pkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_3&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3pkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_6&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3
< 4.18.0-348.23.1.el8_5+ 8 more
- (no CPE)range: < 4.18.0-348.23.1.el8_5
- (no CPE)range: < 6-150300.2.2
- (no CPE)range: < 7-150300.2.2
- (no CPE)range: < 8-150300.2.2
- (no CPE)range: < 4-150300.2.2
- (no CPE)range: < 10-3.2
- (no CPE)range: < 8-150300.2.2
- (no CPE)range: < 8-150300.2.2
- (no CPE)range: < 4-150300.2.2
cpe:2.3:o:suse:linux_enterprise:15.0:sp3:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:suse:linux_enterprise:15.0:sp3:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise:15.0:sp4:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- bugzilla.suse.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/nvdMailing ListPatchVendor Advisory
- lkml.org/lkml/2021/10/4/697nvdMailing ListPatchVendor Advisory
- access.redhat.com/security/cve/CVE-2021-4028nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- security.netapp.com/advisory/ntap-20221228-0002/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.