QID 377702

Date Published: 2022-10-31

QID 377702: F5 BIG-IP Linux kernel vulnerability for cve-2021-4083 (K52379673)

A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.CVE-2021-4083

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.7
14.1.0 - 14.1.5
13.1.0 - 13.1.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

This flaw allows a local user to cause the system to become unresponsive or to escalate their privileges on the system.

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    For more information about patch details please refer to K52379673
    Vendor References

    CVEs related to QID 377702

    Software Advisories
    Advisory ID Software Component Link
    K52379673 URL Logo support.f5.com/csp/article/K52379673