PT-2021-8009 · Linux+1 · Linux Kernel+1

Published

2021-05-04

·

Updated

2024-12-10

·

CVE-2021-47068

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use-after-free bug in the NFC subsystem of the Linux kernel, specifically in the llcp sock bind and llcp sock connect functions. This can be triggered when the same local is assigned to two different sockets, leading to a potential denial of service or information disclosure. The bug can be exploited by creating two sockets and binding them to the same address, then closing the sockets. The nfc llcp local put function is involved in the issue, and assigning NULL to llcp sock->local after calling this function can fix the problem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01812
CVE-2021-47068
OPENSUSE-SU-2024_1489-1
SUSE-SU-2024:1454-1
SUSE-SU-2024:1465-1
SUSE-SU-2024:1489-1
SUSE-SU-2024:1643-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1870-1

Affected Products

Linux Kernel
Suse