CVE-2021-3483Use After Free in Kernel

CWE-416Use After Free16 documents8 sources
Severity
7.8HIGHNVD
OSV6.5OSV5.4
EPSS
0.2%
top 62.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateFeb 27

Description

A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel< 5.12+1
Debianlinux/linux_kernel< 5.10.28-1+3
Ubuntulinux/linux_kernel< 5.4.0-74.83+2
CVEListV5linux/linux_kernelkernel 5.12-rc6

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

7
GHSA
GHSA-jvqw-v5h3-ccw4: A flaw was found in the Nosy driver in the Linux kernel2022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-02-22
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities2021-06-08
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.2021-06-08

📋Vendor Advisories

7
Ubuntu
Linux kernel vulnerabilities2022-03-22
Ubuntu
Linux kernel vulnerabilities2022-02-22
Ubuntu
Linux kernel vulnerabilities2021-06-08
Ubuntu
Linux kernel (OEM) vulnerabilities2021-05-11
Microsoft
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list leading to a use-after-free when one of these devices is removed. The2021-05-11

💬Community

1
Bugzilla
CVE-2021-46924 kernel: NFC: st21nfca: Fix memory leak in device probe and remove2024-02-27
CVE-2021-3483 — Use After Free in Linux Kernel | cvebase