CVE-2021-4083
Publication date 18 January 2022
Last updated 10 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.
From the Ubuntu Security Team
Jann Horn discovered a race condition in the Unix domain socket implementation in the Linux kernel that could result in a read-after-free. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
Why is this CVE high priority?
See ubuntu cvss score
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| linux | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Fixed 5.4.0-100.113
|
|
| 18.04 LTS bionic |
Fixed 4.15.0-169.177
|
|
| 16.04 LTS xenial |
Fixed 4.4.0-223.256
|
|
| 14.04 LTS trusty |
Vulnerable
|
|
| linux-gke | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Fixed 5.4.0-1063.66
|
|
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Ignored end of standard support | |
| 14.04 LTS trusty | Not in release | |
| linux-azure-fde-5.15 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release |