PT-2021-3771 · Linux+9 · Linux Kernel+9

Published

2020-10-02

·

Updated

2025-03-11

·

CVE-2021-37159

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.13.4
Description The issue is related to the hso free net device function in the Linux kernel's drivers/net/usb/hso.c file, which calls unregister netdev without checking for the NETREG REGISTERED state. This leads to a use-after-free and a double free, potentially allowing an attacker to impact confidentiality, integrity, and availability.
Recommendations For Linux kernel versions through 5.13.4, consider updating to a version that includes a fix for this issue, as the current version may allow for exploitation due to the hso free net device function's behavior. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Double Free

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1988
ALT-PU-2021-2415
ALT-PU-2021-2486
ALT-PU-2021-2616
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-6578
BDU:2021-04027
CESA-2022_1975
CESA-2022_1988
CVE-2021-37159
DLA-2785-1
DLA-2843-1
OPENSUSE-SU-2021:1501-1
OPENSUSE-SU-2021:3675-1
OPENSUSE-SU-2021:3806-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_1501-1
OPENSUSE-SU-2021_3675-1
OPENSUSE-SU-2021_3806-1
OPENSUSE-SU-2021_3876-1
RHSA-2022:1975
RHSA-2022:1988
RHSA-2022_1975
RHSA-2022_1988
RLSA-2022:1975
RLSA-2022:1988
SUSE-SU-2021:14849-1
SUSE-SU-2021:3675-1
SUSE-SU-2021:3723-1
SUSE-SU-2021:3748-1
SUSE-SU-2021:3806-1
SUSE-SU-2021:3807-1
SUSE-SU-2021:3848-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3929-1
SUSE-SU-2021:3933-1
SUSE-SU-2021:3935-1
SUSE-SU-2021:3969-1
SUSE-SU-2021:3972-1
SUSE-SU-2021:3978-1
SUSE-SU-2021_14849-1
SUSE-SU-2025:0834-1
SUSE-SU-2025_0834-1
USN-5092-1
USN-5092-2
USN-5092-3
USN-5096-1
USN-5115-1
USN-5163-1
USN-5164-1
USN-5361-1
USN-6971-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu