CVE-2021-23134
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: psirt@paloaltonetworks.com (Secondary)
Description
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.12.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
References (14)
Source: psirt@paloaltonetworks.com
Mailing ListPatchVendor Advisory
Source: psirt@paloaltonetworks.com
Mailing ListThird Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListThird Party Advisory
Source: psirt@paloaltonetworks.com
Source: psirt@paloaltonetworks.com
Source: psirt@paloaltonetworks.com
Third Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Timeline
No history available yet.