CVE-2021-47069 (GCVE-0-2021-47069)
Vulnerability from cvelistv5
Published
2024-03-01 21:15
Modified
2026-08-05 08:45
Summary
In the Linux kernel, the following vulnerability has been resolved: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry do_mq_timedreceive calls wq_sleep with a stack local address. The sender (do_mq_timedsend) uses this address to later call pipelined_send. This leads to a very hard to trigger race where a do_mq_timedreceive call might return and leave do_mq_timedsend to rely on an invalid address, causing the following crash: RIP: 0010:wake_q_add_safe+0x13/0x60 Call Trace: __x64_sys_mq_timedsend+0x2a9/0x490 do_syscall_64+0x80/0x680 entry_SYSCALL_64_after_hwframe+0x44/0xa9 RIP: 0033:0x7f5928e40343 The race occurs as: 1. do_mq_timedreceive calls wq_sleep with the address of `struct ext_wait_queue` on function stack (aliased as `ewq_addr` here) - it holds a valid `struct ext_wait_queue *` as long as the stack has not been overwritten. 2. `ewq_addr` gets added to info->e_wait_q[RECV].list in wq_add, and do_mq_timedsend receives it via wq_get_first_waiter(info, RECV) to call __pipelined_op. 3. Sender calls __pipelined_op::smp_store_release(&this->state, STATE_READY). Here is where the race window begins. (`this` is `ewq_addr`.) 4. If the receiver wakes up now in do_mq_timedreceive::wq_sleep, it will see `state == STATE_READY` and break. 5. do_mq_timedreceive returns, and `ewq_addr` is no longer guaranteed to be a `struct ext_wait_queue *` since it was on do_mq_timedreceive's stack. (Although the address may not get overwritten until another function happens to touch it, which means it can persist around for an indefinite time.) 6. do_mq_timedsend::__pipelined_op() still believes `ewq_addr` is a `struct ext_wait_queue *`, and uses it to find a task_struct to pass to the wake_q_add_safe call. In the lucky case where nothing has overwritten `ewq_addr` yet, `ewq_addr->task` is the right task_struct. In the unlucky case, __pipelined_op::wake_q_add_safe gets handed a bogus address as the receiver's task_struct causing the crash. do_mq_timedsend::__pipelined_op() should not dereference `this` after setting STATE_READY, as the receiver counterpart is now free to return. Change __pipelined_op to call wake_q_add_safe on the receiver's task_struct returned by get_task_struct, instead of dereferencing `this` which sits on the receiver's stack. As Manfred pointed out, the race potentially also exists in ipc/msg.c::expunge_all and ipc/sem.c::wake_up_sem_queue_prepare. Fix those in the same way.
Impacted products
Vendor Product Version
Linux Linux Version: c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04
Version: c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04
Version: c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2021-47069",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-21T16:15:09.996738Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-21T16:15:20.262Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T05:24:39.653Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/4528c0c323085e645b8765913b4a7fd42cf49b65"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/807fa14536b26803b858da878b643be72952a097"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/a11ddb37bf367e6b5239b95ca759e5389bb46048"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "ipc/mqueue.c",
            "ipc/msg.c",
            "ipc/sem.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4528c0c323085e645b8765913b4a7fd42cf49b65",
              "status": "affected",
              "version": "c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04",
              "versionType": "git"
            },
            {
              "lessThan": "807fa14536b26803b858da878b643be72952a097",
              "status": "affected",
              "version": "c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04",
              "versionType": "git"
            },
            {
              "lessThan": "a11ddb37bf367e6b5239b95ca759e5389bb46048",
              "status": "affected",
              "version": "c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "ipc/mqueue.c",
            "ipc/msg.c",
            "ipc/sem.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.6"
            },
            {
              "lessThan": "5.6",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.40",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.12.*",
              "status": "unaffected",
              "version": "5.12.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "5.13",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.40",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.12.7",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.13",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry\n\ndo_mq_timedreceive calls wq_sleep with a stack local address.  The\nsender (do_mq_timedsend) uses this address to later call pipelined_send.\n\nThis leads to a very hard to trigger race where a do_mq_timedreceive\ncall might return and leave do_mq_timedsend to rely on an invalid\naddress, causing the following crash:\n\n  RIP: 0010:wake_q_add_safe+0x13/0x60\n  Call Trace:\n   __x64_sys_mq_timedsend+0x2a9/0x490\n   do_syscall_64+0x80/0x680\n   entry_SYSCALL_64_after_hwframe+0x44/0xa9\n  RIP: 0033:0x7f5928e40343\n\nThe race occurs as:\n\n1. do_mq_timedreceive calls wq_sleep with the address of `struct\n   ext_wait_queue` on function stack (aliased as `ewq_addr` here) - it\n   holds a valid `struct ext_wait_queue *` as long as the stack has not\n   been overwritten.\n\n2. `ewq_addr` gets added to info-\u003ee_wait_q[RECV].list in wq_add, and\n   do_mq_timedsend receives it via wq_get_first_waiter(info, RECV) to call\n   __pipelined_op.\n\n3. Sender calls __pipelined_op::smp_store_release(\u0026this-\u003estate,\n   STATE_READY).  Here is where the race window begins.  (`this` is\n   `ewq_addr`.)\n\n4. If the receiver wakes up now in do_mq_timedreceive::wq_sleep, it\n   will see `state == STATE_READY` and break.\n\n5. do_mq_timedreceive returns, and `ewq_addr` is no longer guaranteed\n   to be a `struct ext_wait_queue *` since it was on do_mq_timedreceive\u0027s\n   stack.  (Although the address may not get overwritten until another\n   function happens to touch it, which means it can persist around for an\n   indefinite time.)\n\n6. do_mq_timedsend::__pipelined_op() still believes `ewq_addr` is a\n   `struct ext_wait_queue *`, and uses it to find a task_struct to pass to\n   the wake_q_add_safe call.  In the lucky case where nothing has\n   overwritten `ewq_addr` yet, `ewq_addr-\u003etask` is the right task_struct.\n   In the unlucky case, __pipelined_op::wake_q_add_safe gets handed a\n   bogus address as the receiver\u0027s task_struct causing the crash.\n\ndo_mq_timedsend::__pipelined_op() should not dereference `this` after\nsetting STATE_READY, as the receiver counterpart is now free to return.\nChange __pipelined_op to call wake_q_add_safe on the receiver\u0027s\ntask_struct returned by get_task_struct, instead of dereferencing `this`\nwhich sits on the receiver\u0027s stack.\n\nAs Manfred pointed out, the race potentially also exists in\nipc/msg.c::expunge_all and ipc/sem.c::wake_up_sem_queue_prepare.  Fix\nthose in the same way."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is triggered through local IPC syscalls (mq_timedsend/mq_timedreceive, msgsnd/msgrcv/msgctl, semop/semctl) and is not reachable by processing remote or adjacent-link network traffic.\nAC:L - The attacker fully controls both sides of the race by running concurrent sender and receiver (or RMID) operations on their own message queue or semaphore set, so success does not depend on an external condition outside their influence.\nPR:L - An unprivileged local user can mq_open/msgget/semget their own objects and exercise send/receive/RMID paths; CAP_SYS_RESOURCE is only needed to exceed resource limits, not to hit the vulnerable code.\nUI:N - The attacker performs the concurrent IPC operations themselves and does not need any separate victim or administrator action.\nS:U - This is a standard in-kernel stack use-after-free within the host OS authority and does not cross a VM, IOMMU, or other security boundary.\nC:H - The dangling stack pointer is reloaded into wake_q_add_safe as a task_struct *, and this stack UAF can be leveraged via stack reuse/heap primitives for arbitrary kernel memory disclosure under UAF scoring guidance.\nI:H - wake_q_add_safe/__wake_q_add perform cmpxchg and list writes through the attacker-influenced task pointer and may put_task_struct/wake_up_process on a bogus object, yielding write and control-flow hijack primitives.\nA:H - The issue was observed to crash in wake_q_add_safe with a bogus task_struct pointer, so kernel oops/panic availability impact is High even without a full exploit."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:45:50.647Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4528c0c323085e645b8765913b4a7fd42cf49b65"
        },
        {
          "url": "https://git.kernel.org/stable/c/807fa14536b26803b858da878b643be72952a097"
        },
        {
          "url": "https://git.kernel.org/stable/c/a11ddb37bf367e6b5239b95ca759e5389bb46048"
        }
      ],
      "title": "ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2021-47069",
    "datePublished": "2024-03-01T21:15:08.598Z",
    "dateReserved": "2024-02-29T22:33:44.296Z",
    "dateUpdated": "2026-08-05T08:45:50.647Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/4528c0c323085e645b8765913b4a7fd42cf49b65\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/807fa14536b26803b858da878b643be72952a097\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/a11ddb37bf367e6b5239b95ca759e5389bb46048\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-04T05:24:39.653Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2021-47069\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-06-21T16:15:09.996738Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-21T16:15:15.682Z\"}}], \"cna\": {\"title\": \"ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The bug is triggered through local IPC syscalls (mq_timedsend/mq_timedreceive, msgsnd/msgrcv/msgctl, semop/semctl) and is not reachable by processing remote or adjacent-link network traffic.\\nAC:L - The attacker fully controls both sides of the race by running concurrent sender and receiver (or RMID) operations on their own message queue or semaphore set, so success does not depend on an external condition outside their influence.\\nPR:L - An unprivileged local user can mq_open/msgget/semget their own objects and exercise send/receive/RMID paths; CAP_SYS_RESOURCE is only needed to exceed resource limits, not to hit the vulnerable code.\\nUI:N - The attacker performs the concurrent IPC operations themselves and does not need any separate victim or administrator action.\\nS:U - This is a standard in-kernel stack use-after-free within the host OS authority and does not cross a VM, IOMMU, or other security boundary.\\nC:H - The dangling stack pointer is reloaded into wake_q_add_safe as a task_struct *, and this stack UAF can be leveraged via stack reuse/heap primitives for arbitrary kernel memory disclosure under UAF scoring guidance.\\nI:H - wake_q_add_safe/__wake_q_add perform cmpxchg and list writes through the attacker-influenced task pointer and may put_task_struct/wake_up_process on a bogus object, yielding write and control-flow hijack primitives.\\nA:H - The issue was observed to crash in wake_q_add_safe with a bogus task_struct pointer, so kernel oops/panic availability impact is High even without a full exploit.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04\", \"lessThan\": \"4528c0c323085e645b8765913b4a7fd42cf49b65\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04\", \"lessThan\": \"807fa14536b26803b858da878b643be72952a097\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c5b2cbdbdac563f46ecd5e187253ab1abbd6fc04\", \"lessThan\": \"a11ddb37bf367e6b5239b95ca759e5389bb46048\", \"versionType\": \"git\"}], \"programFiles\": [\"ipc/mqueue.c\", \"ipc/msg.c\", \"ipc/sem.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.6\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.6\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.10.40\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.12.7\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.12.*\"}, {\"status\": \"unaffected\", \"version\": \"5.13\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"ipc/mqueue.c\", \"ipc/msg.c\", \"ipc/sem.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/4528c0c323085e645b8765913b4a7fd42cf49b65\"}, {\"url\": \"https://git.kernel.org/stable/c/807fa14536b26803b858da878b643be72952a097\"}, {\"url\": \"https://git.kernel.org/stable/c/a11ddb37bf367e6b5239b95ca759e5389bb46048\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry\\n\\ndo_mq_timedreceive calls wq_sleep with a stack local address.  The\\nsender (do_mq_timedsend) uses this address to later call pipelined_send.\\n\\nThis leads to a very hard to trigger race where a do_mq_timedreceive\\ncall might return and leave do_mq_timedsend to rely on an invalid\\naddress, causing the following crash:\\n\\n  RIP: 0010:wake_q_add_safe+0x13/0x60\\n  Call Trace:\\n   __x64_sys_mq_timedsend+0x2a9/0x490\\n   do_syscall_64+0x80/0x680\\n   entry_SYSCALL_64_after_hwframe+0x44/0xa9\\n  RIP: 0033:0x7f5928e40343\\n\\nThe race occurs as:\\n\\n1. do_mq_timedreceive calls wq_sleep with the address of `struct\\n   ext_wait_queue` on function stack (aliased as `ewq_addr` here) - it\\n   holds a valid `struct ext_wait_queue *` as long as the stack has not\\n   been overwritten.\\n\\n2. `ewq_addr` gets added to info-\u003ee_wait_q[RECV].list in wq_add, and\\n   do_mq_timedsend receives it via wq_get_first_waiter(info, RECV) to call\\n   __pipelined_op.\\n\\n3. Sender calls __pipelined_op::smp_store_release(\u0026this-\u003estate,\\n   STATE_READY).  Here is where the race window begins.  (`this` is\\n   `ewq_addr`.)\\n\\n4. If the receiver wakes up now in do_mq_timedreceive::wq_sleep, it\\n   will see `state == STATE_READY` and break.\\n\\n5. do_mq_timedreceive returns, and `ewq_addr` is no longer guaranteed\\n   to be a `struct ext_wait_queue *` since it was on do_mq_timedreceive\u0027s\\n   stack.  (Although the address may not get overwritten until another\\n   function happens to touch it, which means it can persist around for an\\n   indefinite time.)\\n\\n6. do_mq_timedsend::__pipelined_op() still believes `ewq_addr` is a\\n   `struct ext_wait_queue *`, and uses it to find a task_struct to pass to\\n   the wake_q_add_safe call.  In the lucky case where nothing has\\n   overwritten `ewq_addr` yet, `ewq_addr-\u003etask` is the right task_struct.\\n   In the unlucky case, __pipelined_op::wake_q_add_safe gets handed a\\n   bogus address as the receiver\u0027s task_struct causing the crash.\\n\\ndo_mq_timedsend::__pipelined_op() should not dereference `this` after\\nsetting STATE_READY, as the receiver counterpart is now free to return.\\nChange __pipelined_op to call wake_q_add_safe on the receiver\u0027s\\ntask_struct returned by get_task_struct, instead of dereferencing `this`\\nwhich sits on the receiver\u0027s stack.\\n\\nAs Manfred pointed out, the race potentially also exists in\\nipc/msg.c::expunge_all and ipc/sem.c::wake_up_sem_queue_prepare.  Fix\\nthose in the same way.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.40\", \"versionStartIncluding\": \"5.6\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.12.7\", \"versionStartIncluding\": \"5.6\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.13\", \"versionStartIncluding\": \"5.6\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T08:45:50.647Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2021-47069\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T08:45:50.647Z\", \"dateReserved\": \"2024-02-29T22:33:44.296Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-03-01T21:15:08.598Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…