A read-after-free memory flaw was found in the Linux kernel's garbage collection
39128
06 October 2026
06 October 2026
CLOSED
LOW
7.0 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2021-4083
|
Brocade Security Advisory ID |
BSA-2026-1719 |
|
Component |
CLI |
|
CWE |
CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
|
|
|
Summary
A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.
Products Affected
- Brocade SANnav versions before 2.2.1
- Brocade ASCG versions before 3.0.0
Products Not Affected
- Brocade Fabric OS versions before 10.0.0
[VEX Justification: Vulnerable_code_cannot_be_contolled_by_adversary ]
Solution
- While Brocade Fabric OS is not exploitable, security update provided in Brocade Fabric OS versions 9.2.2d and 10.0.0
- Security update provided in Brocade SANnav 2.2.1
- Security update provided in Brocade ASCG 3.0.0
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
10/06/2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.