{"api_version":"1","generated_at":"2026-08-04T14:27:54+00:00","cve":"CVE-2021-46936","urls":{"html":"https://cve.report/CVE-2021-46936","api":"https://cve.report/api/cve/CVE-2021-46936.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-46936","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-46936"},"summary":{"title":"net: fix use-after-free in tw_timer_handler","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix use-after-free in tw_timer_handler\n\nA real world panic issue was found as follow in Linux 5.4.\n\n    BUG: unable to handle page fault for address: ffffde49a863de28\n    PGD 7e6fe62067 P4D 7e6fe62067 PUD 7e6fe63067 PMD f51e064067 PTE 0\n    RIP: 0010:tw_timer_handler+0x20/0x40\n    Call Trace:\n     <IRQ>\n     call_timer_fn+0x2b/0x120\n     run_timer_softirq+0x1ef/0x450\n     __do_softirq+0x10d/0x2b8\n     irq_exit+0xc7/0xd0\n     smp_apic_timer_interrupt+0x68/0x120\n     apic_timer_interrupt+0xf/0x20\n\nThis issue was also reported since 2017 in the thread [1],\nunfortunately, the issue was still can be reproduced after fixing\nDCCP.\n\nThe ipv4_mib_exit_net is called before tcp_sk_exit_batch when a net\nnamespace is destroyed since tcp_sk_ops is registered befrore\nipv4_mib_ops, which means tcp_sk_ops is in the front of ipv4_mib_ops\nin the list of pernet_list. There will be a use-after-free on\nnet->mib.net_statistics in tw_timer_handler after ipv4_mib_exit_net\nif there are some inflight time-wait timers.\n\nThis bug is not introduced by commit f2bf415cfed7 (\"mib: add net to\nNET_ADD_STATS_BH\") since the net_statistics is a global variable\ninstead of dynamic allocation and freeing. Actually, commit\n61a7e26028b9 (\"mib: put net statistics on struct net\") introduces\nthe bug since it put net statistics on struct net and free it when\nnet namespace is destroyed.\n\nMoving init_ipv4_mibs() to the front of tcp_init() to fix this bug\nand replace pr_crit() with panic() since continuing is meaningless\nwhen init_ipv4_mibs() fails.\n\n[1] https://groups.google.com/g/syzkaller/c/p1tn-_Kc6l4/m/smuL_FMAAgAJ?pli=1","state":"PUBLISHED","assigner":"Linux","published_at":"2024-02-27 10:15:08","updated_at":"2026-08-04 10:16:37"},"problem_types":["CWE-416"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/08eacbd141e2495d2fcdde84358a06c4f95cbb13","name":"https://git.kernel.org/stable/c/08eacbd141e2495d2fcdde84358a06c4f95cbb13","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fe5838c22b986c1190f1dce9aa09bf6a491c1a69","name":"https://git.kernel.org/stable/c/fe5838c22b986c1190f1dce9aa09bf6a491c1a69","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5c2fe20ad37ff56070ae0acb34152333976929b4","name":"https://git.kernel.org/stable/c/5c2fe20ad37ff56070ae0acb34152333976929b4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e22e45fc9e41bf9fcc1e92cfb78eb92786728ef0","name":"https://git.kernel.org/stable/c/e22e45fc9e41bf9fcc1e92cfb78eb92786728ef0","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2386e81a1d277f540e1285565c9d41d531bb69d4","name":"https://git.kernel.org/stable/c/2386e81a1d277f540e1285565c9d41d531bb69d4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a8e1944b44f94f5c5f530e434c5eaee787254566","name":"https://git.kernel.org/stable/c/a8e1944b44f94f5c5f530e434c5eaee787254566","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/15579e1301f856ad9385d720c9267c11032a5022","name":"https://git.kernel.org/stable/c/15579e1301f856ad9385d720c9267c11032a5022","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e73164e89d1be561228a4534e1091369ee4ba41a","name":"https://git.kernel.org/stable/c/e73164e89d1be561228a4534e1091369ee4ba41a","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-46936","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-46936","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61a7e26028b94805fd686a6dc9dbd9941f8f19b0 15579e1301f856ad9385d720c9267c11032a5022 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61a7e26028b94805fd686a6dc9dbd9941f8f19b0 e73164e89d1be561228a4534e1091369ee4ba41a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61a7e26028b94805fd686a6dc9dbd9941f8f19b0 5c2fe20ad37ff56070ae0acb34152333976929b4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61a7e26028b94805fd686a6dc9dbd9941f8f19b0 a8e1944b44f94f5c5f530e434c5eaee787254566 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61a7e26028b94805fd686a6dc9dbd9941f8f19b0 fe5838c22b986c1190f1dce9aa09bf6a491c1a69 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61a7e26028b94805fd686a6dc9dbd9941f8f19b0 2386e81a1d277f540e1285565c9d41d531bb69d4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61a7e26028b94805fd686a6dc9dbd9941f8f19b0 08eacbd141e2495d2fcdde84358a06c4f95cbb13 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61a7e26028b94805fd686a6dc9dbd9941f8f19b0 e22e45fc9e41bf9fcc1e92cfb78eb92786728ef0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.27","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.27 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.4.298 4.4.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.9.296 4.9.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.14.261 4.14.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.19.224 4.19.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.4.170 5.4.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.90 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.13 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.16 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"46936","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-04T05:17:42.878Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/15579e1301f856ad9385d720c9267c11032a5022"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/e73164e89d1be561228a4534e1091369ee4ba41a"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/5c2fe20ad37ff56070ae0acb34152333976929b4"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/a8e1944b44f94f5c5f530e434c5eaee787254566"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/fe5838c22b986c1190f1dce9aa09bf6a491c1a69"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/2386e81a1d277f540e1285565c9d41d531bb69d4"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/08eacbd141e2495d2fcdde84358a06c4f95cbb13"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/e22e45fc9e41bf9fcc1e92cfb78eb92786728ef0"}],"title":"CVE Program Container"},{"metrics":[{"other":{"content":{"id":"CVE-2021-46936","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-09-10T16:01:57.788399Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-09-11T17:33:18.637Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/ipv4/af_inet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"15579e1301f856ad9385d720c9267c11032a5022","status":"affected","version":"61a7e26028b94805fd686a6dc9dbd9941f8f19b0","versionType":"git"},{"lessThan":"e73164e89d1be561228a4534e1091369ee4ba41a","status":"affected","version":"61a7e26028b94805fd686a6dc9dbd9941f8f19b0","versionType":"git"},{"lessThan":"5c2fe20ad37ff56070ae0acb34152333976929b4","status":"affected","version":"61a7e26028b94805fd686a6dc9dbd9941f8f19b0","versionType":"git"},{"lessThan":"a8e1944b44f94f5c5f530e434c5eaee787254566","status":"affected","version":"61a7e26028b94805fd686a6dc9dbd9941f8f19b0","versionType":"git"},{"lessThan":"fe5838c22b986c1190f1dce9aa09bf6a491c1a69","status":"affected","version":"61a7e26028b94805fd686a6dc9dbd9941f8f19b0","versionType":"git"},{"lessThan":"2386e81a1d277f540e1285565c9d41d531bb69d4","status":"affected","version":"61a7e26028b94805fd686a6dc9dbd9941f8f19b0","versionType":"git"},{"lessThan":"08eacbd141e2495d2fcdde84358a06c4f95cbb13","status":"affected","version":"61a7e26028b94805fd686a6dc9dbd9941f8f19b0","versionType":"git"},{"lessThan":"e22e45fc9e41bf9fcc1e92cfb78eb92786728ef0","status":"affected","version":"61a7e26028b94805fd686a6dc9dbd9941f8f19b0","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/ipv4/af_inet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.27"},{"lessThan":"2.6.27","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"4.4.*","status":"unaffected","version":"4.4.298","versionType":"semver"},{"lessThanOrEqual":"4.9.*","status":"unaffected","version":"4.9.296","versionType":"semver"},{"lessThanOrEqual":"4.14.*","status":"unaffected","version":"4.14.261","versionType":"semver"},{"lessThanOrEqual":"4.19.*","status":"unaffected","version":"4.19.224","versionType":"semver"},{"lessThanOrEqual":"5.4.*","status":"unaffected","version":"5.4.170","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.90","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.13","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"5.16","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.4.298","versionStartIncluding":"2.6.27","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.9.296","versionStartIncluding":"2.6.27","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.14.261","versionStartIncluding":"2.6.27","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.19.224","versionStartIncluding":"2.6.27","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.4.170","versionStartIncluding":"2.6.27","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.90","versionStartIncluding":"2.6.27","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.13","versionStartIncluding":"2.6.27","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.16","versionStartIncluding":"2.6.27","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix use-after-free in tw_timer_handler\n\nA real world panic issue was found as follow in Linux 5.4.\n\n    BUG: unable to handle page fault for address: ffffde49a863de28\n    PGD 7e6fe62067 P4D 7e6fe62067 PUD 7e6fe63067 PMD f51e064067 PTE 0\n    RIP: 0010:tw_timer_handler+0x20/0x40\n    Call Trace:\n     <IRQ>\n     call_timer_fn+0x2b/0x120\n     run_timer_softirq+0x1ef/0x450\n     __do_softirq+0x10d/0x2b8\n     irq_exit+0xc7/0xd0\n     smp_apic_timer_interrupt+0x68/0x120\n     apic_timer_interrupt+0xf/0x20\n\nThis issue was also reported since 2017 in the thread [1],\nunfortunately, the issue was still can be reproduced after fixing\nDCCP.\n\nThe ipv4_mib_exit_net is called before tcp_sk_exit_batch when a net\nnamespace is destroyed since tcp_sk_ops is registered befrore\nipv4_mib_ops, which means tcp_sk_ops is in the front of ipv4_mib_ops\nin the list of pernet_list. There will be a use-after-free on\nnet->mib.net_statistics in tw_timer_handler after ipv4_mib_exit_net\nif there are some inflight time-wait timers.\n\nThis bug is not introduced by commit f2bf415cfed7 (\"mib: add net to\nNET_ADD_STATS_BH\") since the net_statistics is a global variable\ninstead of dynamic allocation and freeing. Actually, commit\n61a7e26028b9 (\"mib: put net statistics on struct net\") introduces\nthe bug since it put net statistics on struct net and free it when\nnet namespace is destroyed.\n\nMoving init_ipv4_mibs() to the front of tcp_init() to fix this bug\nand replace pr_crit() with panic() since continuing is meaningless\nwhen init_ipv4_mibs() fails.\n\n[1] https://groups.google.com/g/syzkaller/c/p1tn-_Kc6l4/m/smuL_FMAAgAJ?pli=1"}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-08-04T08:57:55.042Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/15579e1301f856ad9385d720c9267c11032a5022"},{"url":"https://git.kernel.org/stable/c/e73164e89d1be561228a4534e1091369ee4ba41a"},{"url":"https://git.kernel.org/stable/c/5c2fe20ad37ff56070ae0acb34152333976929b4"},{"url":"https://git.kernel.org/stable/c/a8e1944b44f94f5c5f530e434c5eaee787254566"},{"url":"https://git.kernel.org/stable/c/fe5838c22b986c1190f1dce9aa09bf6a491c1a69"},{"url":"https://git.kernel.org/stable/c/2386e81a1d277f540e1285565c9d41d531bb69d4"},{"url":"https://git.kernel.org/stable/c/08eacbd141e2495d2fcdde84358a06c4f95cbb13"},{"url":"https://git.kernel.org/stable/c/e22e45fc9e41bf9fcc1e92cfb78eb92786728ef0"}],"title":"net: fix use-after-free in tw_timer_handler","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2021-46936","datePublished":"2024-02-27T09:44:02.758Z","dateReserved":"2024-02-25T13:45:52.720Z","dateUpdated":"2026-08-04T08:57:55.042Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-02-27 10:15:08","lastModifiedDate":"2026-08-04 10:16:37","problem_types":["CWE-416"],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-10T16:01:57.788399Z","id":"CVE-2021-46936","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.27","versionEndExcluding":"4.4.298","matchCriteriaId":"0B63EF4E-6C8F-4CCD-A30C-09E949BDD667"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5.0","versionEndExcluding":"4.9.296","matchCriteriaId":"883CB22B-11DA-4D54-8121-3F5494EDBD4C"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10.0","versionEndExcluding":"4.14.261","matchCriteriaId":"B5D4F856-5F69-4F4A-911F-50A21B9A68B6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15.0","versionEndExcluding":"4.19.224","matchCriteriaId":"B34A1353-506A-4AB9-87EC-CD50F09DFB8A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20.0","versionEndExcluding":"5.4.170","matchCriteriaId":"56D16FBB-453E-4316-A027-E517828203D7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.0","versionEndExcluding":"5.10.90","matchCriteriaId":"C87FB3FD-3E74-4588-A1A4-B9BA8AE0C06B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11.0","versionEndExcluding":"5.15.13","matchCriteriaId":"083E0940-932B-447B-A6B2-677DAE27FD04"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"46936","Ordinal":"1","Title":"net: fix use-after-free in tw_timer_handler","CVE":"CVE-2021-46936","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"46936","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix use-after-free in tw_timer_handler\n\nA real world panic issue was found as follow in Linux 5.4.\n\n    BUG: unable to handle page fault for address: ffffde49a863de28\n    PGD 7e6fe62067 P4D 7e6fe62067 PUD 7e6fe63067 PMD f51e064067 PTE 0\n    RIP: 0010:tw_timer_handler+0x20/0x40\n    Call Trace:\n     <IRQ>\n     call_timer_fn+0x2b/0x120\n     run_timer_softirq+0x1ef/0x450\n     __do_softirq+0x10d/0x2b8\n     irq_exit+0xc7/0xd0\n     smp_apic_timer_interrupt+0x68/0x120\n     apic_timer_interrupt+0xf/0x20\n\nThis issue was also reported since 2017 in the thread [1],\nunfortunately, the issue was still can be reproduced after fixing\nDCCP.\n\nThe ipv4_mib_exit_net is called before tcp_sk_exit_batch when a net\nnamespace is destroyed since tcp_sk_ops is registered befrore\nipv4_mib_ops, which means tcp_sk_ops is in the front of ipv4_mib_ops\nin the list of pernet_list. There will be a use-after-free on\nnet->mib.net_statistics in tw_timer_handler after ipv4_mib_exit_net\nif there are some inflight time-wait timers.\n\nThis bug is not introduced by commit f2bf415cfed7 (\"mib: add net to\nNET_ADD_STATS_BH\") since the net_statistics is a global variable\ninstead of dynamic allocation and freeing. Actually, commit\n61a7e26028b9 (\"mib: put net statistics on struct net\") introduces\nthe bug since it put net statistics on struct net and free it when\nnet namespace is destroyed.\n\nMoving init_ipv4_mibs() to the front of tcp_init() to fix this bug\nand replace pr_crit() with panic() since continuing is meaningless\nwhen init_ipv4_mibs() fails.\n\n[1] https://groups.google.com/g/syzkaller/c/p1tn-_Kc6l4/m/smuL_FMAAgAJ?pli=1","Type":"Description","Title":"net: fix use-after-free in tw_timer_handler"}]}}}