cbcvebase.
CVE-2021-23134
published 2021-05-12

CVE-2021-23134: Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.5th percentile
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux
linuxlinux>= 18013007b596771bf5f5e7feee9586fb0386ad14 < ccddad6dd28530e716448e594c9ca7c76ccd0570ccddad6dd28530e716448e594c9ca7c76ccd0570
linuxlinux>= 4.14.231 < 4.14.2334.14.233
linuxlinux>= 4.19.187 < 4.19.1914.19.191
linuxlinux>= 4.4.267 < 4.4.2694.4.269
linuxlinux>= 4.9.267 < 4.9.2694.9.269
linuxlinux>= 5.10.30 < 5.10.375.10.37
linuxlinux>= 5.11.14 < 5.11.215.11.21
linuxlinux>= 5.4.112 < 5.4.1195.4.119
linuxlinux>= 538a6ff11516d38a61e237d2d2dc04c30c845fbe < 18ae4a192a4496e48a5490b52812645d2413307c18ae4a192a4496e48a5490b52812645d2413307c
linuxlinux>= 6fb003e5ae18d8cda4c8a1175d9dd8db12bec049 < 6b7021ed36dabf29e56842e3408781cd3b82ef6e6b7021ed36dabf29e56842e3408781cd3b82ef6e
linuxlinux>= 8c9e4971e142e2899606a2490b77a1208c1f4638 < 374cdde4dcc9c909a60713abdbbf96d5e3e09f91374cdde4dcc9c909a60713abdbbf96d5e3e09f91
linuxlinux>= a1cdd18c49d23ec38097ac2c5b0d761146fc0109 < 26157c82ba756767b2bd66d28a71b1bc454447f626157c82ba756767b2bd66d28a71b1bc454447f6
linuxlinux>= adbb1d218c5f56dbae052765da83c0f57fce2a31 < 48fba458fe54cc2a980a05c13e6c19b8b2cfb61048fba458fe54cc2a980a05c13e6c19b8b2cfb610
linuxlinux>= c33b1cc62ac05c1dbb1cdafe2eb66da01c76ca8d < 18175fe17ae043a0b81e5d511f8817825784c29918175fe17ae043a0b81e5d511f8817825784c299
linuxlinux>= c33b1cc62ac05c1dbb1cdafe2eb66da01c76ca8d < c61760e6940dd4039a7f5e84a6afc9cdbf4d82b6c61760e6940dd4039a7f5e84a6afc9cdbf4d82b6
linuxlinux>= c89903c9eff219a4695e63715cf922748d743f65 < e32352070bcac22be6ed8ab635debc280bb65b8ce32352070bcac22be6ed8ab635debc280bb65b8c
linuxlinux_kernel< 5.12.45.12.4
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.