CVE-2021-23134
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: psirt@paloaltonetworks.com (Secondary)
Description
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
Affected (18)
Products: Netapp: Cloud Backup, H300s Firmware, H500s Firmware, H700s Firmware, H410s Firmware, H410c Firmware, Solidfire Baseboard Management Controller Firmware · Linux: Linux Kernel · Fedoraproject: Fedora · +1 more
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300s | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500s | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700s | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410c | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Solidfire Baseboard Management Controller | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.269 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
References (14)
Source: psirt@paloaltonetworks.com
Mailing ListPatchVendor Advisory
Source: psirt@paloaltonetworks.com
Mailing ListThird Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListThird Party Advisory
Source: psirt@paloaltonetworks.com
Third Party Advisory
Source: psirt@paloaltonetworks.com
Third Party Advisory
Source: psirt@paloaltonetworks.com
Third Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Timeline
No history available yet.