← Back

CVE-2021-23134

nvd nist
Published: May 12, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: psirt@paloaltonetworks.com (Secondary)

Description

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

Affected (4)

1 product
Linux Kernel
1 product
Fedora
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.12.4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

References (14)

Source: psirt@paloaltonetworks.com
Mailing ListPatchVendor Advisory
Source: psirt@paloaltonetworks.com
Mailing ListThird Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListThird Party Advisory
Source: psirt@paloaltonetworks.com
Third Party Advisory
Source: psirt@paloaltonetworks.com
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory

Timeline

No history available yet.