cbcvebase.
CVE-2021-47017
published 2024-02-28

CVE-2021-47017: In the Linux kernel, the following vulnerability has been resolved: ath10k: Fix a use after free in ath10k_htc_send_bundle In ath10k_htc_send_bundle, the…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ath10k: Fix a use after free in ath10k_htc_send_bundle In ath10k_htc_send_bundle, the bundle_skb could be freed by dev_kfree_skb_any(bundle_skb). But the bundle_skb is used later by bundle_skb->len. As skb_len = bundle_skb->len, my patch replaces bundle_skb->len to skb_len after the bundle_skb was freed.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= c8334512f3dd1b94844baca629f9bedca4271593 < 8bb054fb336f4250002fff4e0b075221c05c3c658bb054fb336f4250002fff4e0b075221c05c3c65
linuxlinux>= c8334512f3dd1b94844baca629f9bedca4271593 < 3b1ac40c6012140828caa79e592a438a18ebf71b3b1ac40c6012140828caa79e592a438a18ebf71b
linuxlinux>= c8334512f3dd1b94844baca629f9bedca4271593 < 5e413c0831ff4700d1739db3fa3ae9f8597446765e413c0831ff4700d1739db3fa3ae9f859744676
linuxlinux>= c8334512f3dd1b94844baca629f9bedca4271593 < 8392df5d7e0b6a7d21440da1fc259f9938f4dec38392df5d7e0b6a7d21440da1fc259f9938f4dec3
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 5.11 < 5.11.215.11.21
linuxlinux_kernel>= 5.12 < 5.12.45.12.4
linuxlinux_kernel>= 5.8 < 5.10.375.10.37

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.