cbcvebase.
CVE-2021-37159
published 2021-07-21

CVE-2021-37159: hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state…

PriorityP426medium6.4CVSS 3.1
AVPACHPRNUINSUCHIHAH
EPSS
0.39%
31.9th percentile
hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux_kernel<= 5.13.4
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 4.15.0-163.1714.15.0-163.171
linuxlinux_kernel>= 0 < 5.4.0-91.1025.4.0-91.102
linuxlinux_kernel>= 0 < 3.13.0-199.2503.13.0-199.250
linuxlinux_kernel>= 0 < 4.4.0-223.2564.4.0-223.256
msrccbl2_kernel_5.15.2.1-1_on_cbl_mariner_2.0
msrccm1_kernel_5.10.131.1-1_on_cbl_mariner_1.0
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_network_exposure_function
oraclecommunications_cloud_native_core_policy
paloaltopan-os

CVSS provenance

nvdv3.16.4MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian6.4MEDIUM
vendor_msrc6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.