CVE-2021-0707
published 2022-04-12CVE-2021-0707: In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.0th percentile
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-155756045References: Upstream kernel
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.9-1 (bookworm) | linux 5.10.9-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 5.10.9-1 | 5.10.9-1 |
| linux | linux_kernel | >= 0 < 5.10.9-1 | 5.10.9-1 |
| linux | linux_kernel | >= 0 < 5.10.9-1 | 5.10.9-1 |
| linux | linux_kernel | >= 0 < 5.10.9-1 | 5.10.9-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2021-0707: dma-buf
vendor_android·2022-04-01·CVSS 7.8
CVE-2021-0707 [HIGH] CVE-2021-0707: dma-buf
Android Security Bulletin 2022-04-01
CVE: CVE-2021-0707
Severity: HIGH
Type: EoP
Component: dma-buf
References: A-155756045
Upstream kernel
Red Hat
Kernel: possible memory corruption due to a use after free in dma_buf_release of dma-buf.c
vendor_redhat·2021-10-07·CVSS 7.8
CVE-2021-0707 [HIGH] CWE-416 Kernel: possible memory corruption due to a use after free in dma_buf_release of dma-buf.c
Kernel: possible memory corruption due to a use after free in dma_buf_release of dma-buf.c
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-155756045References: Upstream kernel
Statement: There was no shipped kernel version that was seen affected by this problem.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise L
Debian
CVE-2021-0707: linux - In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a ...
vendor_debian·2021·CVSS 7.8
CVE-2021-0707 [HIGH] CVE-2021-0707: linux - In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a ...
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-155756045References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.10.9-1)
bullseye: resolved (fixed in 5.10.9-1)
forky: resolved (fixed in 5.10.9-1)
sid: resolved (fixed in 5.10.9-1)
trixie: resolved (fixed in 5.10.9-1)
GHSA
GHSA-28gv-g34g-4v3h: In dma_buf_release of dma-buf
ghsa_unreviewed·2022-04-13
CVE-2021-0707 [HIGH] CWE-416 GHSA-28gv-g34g-4v3h: In dma_buf_release of dma-buf
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-155756045References: Upstream kernel
OSV
CVE-2021-0707: In dma_buf_release of dma-buf
osv·2022-04-12·CVSS 7.8
CVE-2021-0707 [HIGH] CVE-2021-0707: In dma_buf_release of dma-buf
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-155756045References: Upstream kernel
OSV
CVE-2021-0707: In dma_buf_release of dma-buf
osv·2022-04-01
CVE-2021-0707 CVE-2021-0707: In dma_buf_release of dma-buf
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-12
Published