CVE-2021-39713
published 2022-03-16CVE-2021-39713: Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.21%
11.3th percentile
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.2.6-1 (bookworm) | linux 5.2.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 3.13.0-190.241 | 3.13.0-190.241 |
| linux | linux_kernel | >= 0 < 4.4.0-224.257 | 4.4.0-224.257 |
| linux | linux_kernel | >= 0 < 4.4.0-227.261 | 4.4.0-227.261 |
| linux | linux_kernel | >= 0 < 4.15.0-180.189 | 4.15.0-180.189 |
| linux | linux_kernel | >= 0 < 5.4.0-117.132 | 5.4.0-117.132 |
| linux | linux_kernel | >= 0 < 5.15.0-37.39 | 5.15.0-37.39 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-06-16·CVSS 7.0
CVE-2022-21123 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the Linux kernel did not properly restrict access to
the kernel debugger when booted in secure boot environments. A privileged
attacker could use this to bypass UEFI Secure Boot restrictions.
(CVE-2022-21499)
It was discovered that a race condition existed in the network scheduling
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2021-39713)
It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to expose sensitive informa
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2022-06-02·CVSS 7.0
CVE-2022-1055 [HIGH] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
It was discovered that a race condition existed in the network scheduling
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code.(CVE-2021-39713)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges.(CVE-2022-0492)
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-05-12·CVSS 4.7
CVE-2021-4157 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jeremy Cline discovered a use-after-free in the nouveau graphics driver of
the Linux kernel during device removal. A privileged or physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2020-27820)
It was discovered that a race condition existed in the network scheduling
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2021-39713)
It was discovered that the Parallel NFS (pNFS) implementation in the Linux
kernel did not properly perform bounds checking in some situations. An
attacker could use this to cause a
Red Hat
kernel: race condition in the network scheduling subsystem could lead to an use-after-free
vendor_redhat·2022-03-07·CVSS 7.0
CVE-2021-39713 [HIGH] CWE-821 kernel: race condition in the network scheduling subsystem could lead to an use-after-free
kernel: race condition in the network scheduling subsystem could lead to an use-after-free
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
A use-after-free flaw was found in the Linux kernel’s network scheduling subsystem due to a race condition. This flaw allows a local user to cause a denial of service (memory corruption or crash) or privilege escalation.
Statement: This issue affected Linux kernel versions as shipped with Red Hat Enterprise Linux 7 and earlier.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: kernel (Red Hat Enterprise L
Debian
CVE-2021-39713: linux - Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstr...
vendor_debian·2021·CVSS 7.0
CVE-2021-39713 [HIGH] CVE-2021-39713: linux - Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstr...
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
OSV
linux vulnerabilities
osv·2022-06-16·CVSS 7.0
CVE-2022-21499 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that the Linux kernel did not properly restrict access to
the kernel debugger when booted in secure boot environments. A privileged
attacker could use this to bypass UEFI Secure Boot restrictions.
(CVE-2022-21499)
It was discovered that a race condition existed in the network scheduling
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2021-39713)
It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to expose sensitive information. (CVE-2022-21123)
It was discovered that some Intel processors did not com
OSV
Kernel Live Patch Security Notice
osv·2022-06-02·CVSS 7.0
CVE-2021-39713 [HIGH] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
It was discovered that a race condition existed in the network scheduling
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code.(CVE-2021-39713)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges.(CVE-2022-0492)
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code.(CVE-
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2022-05-12·CVSS 4.7
CVE-2020-27820 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Jeremy Cline discovered a use-after-free in the nouveau graphics driver of
the Linux kernel during device removal. A privileged or physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2020-27820)
It was discovered that a race condition existed in the network scheduling
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2021-39713)
It was discovered that the Parallel NFS (pNFS) implementation in the Linux
kernel did not properly perform bounds checking in some situations. An
attacker could use this to cause a denial of service (system crash) or
pos
GHSA
GHSA-5mgm-hh8w-j47p: Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
ghsa_unreviewed·2022-03-17
CVE-2021-39713 [CRITICAL] CWE-362 GHSA-5mgm-hh8w-j47p: Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
OSV
CVE-2021-39713: Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
osv·2022-03-16·CVSS 7.0
CVE-2021-39713 [HIGH] CVE-2021-39713: Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.htmlhttps://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlhttps://source.android.com/security/bulletin/pixel/2022-03-01http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.htmlhttps://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlhttps://source.android.com/security/bulletin/pixel/2022-03-01
2022-03-16
Published