← Back

CVE-2021-33034

nvd nist
Published: May 14, 2021Modified: Aug 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

Affected (10)

1 product
Linux Kernel
1 product
Fedora
1 product
Debian Linux
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Linux
Before 4.4.269
From 4.10 to 4.14.233
From 4.15 to 4.19.191
From 4.20 to 5.4.119
From 4.5 to 4.9.269
From 5.11 to 5.11.21
From 5.12 to 5.12.4
From 5.5 to 5.10.37
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 34
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

References (14)

Source: cve@mitre.org
Mailing ListPatchVendor Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory

Timeline

No history available yet.