Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Linux
Subscribe
|
Linux Kernel
Subscribe
|
|
Netapp
Subscribe
|
Cloud Backup
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410c
Subscribe
H410c Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Solidfire Baseboard Management Controller
Subscribe
Solidfire Baseboard Management Controller Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2689-1 | linux security update |
Debian DLA |
DLA-2690-1 | linux-4.19 security update |
EUVD |
EUVD-2021-10252 | Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability. |
Ubuntu USN |
USN-4997-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4997-2 | Linux kernel (KVM) vulnerabilities |
Ubuntu USN |
USN-5000-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5000-2 | Linux kernel (KVM) vulnerabilities |
Ubuntu USN |
USN-5001-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-5016-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5018-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5343-1 | Linux kernel vulnerabilities |
Fixes
Solution
Apply the following patch: https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c61760e6940d
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-09-17T03:38:10.572Z
Reserved: 2021-01-06T00:00:00.000Z
Link: CVE-2021-23134
No data.
Status : Analyzed
Published: 2021-05-12T23:15:07.707
Modified: 2026-07-30T19:36:37.547
Link: CVE-2021-23134
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN