cbcvebase.
CVE-2021-47306
published 2024-05-21

CVE-2021-47306: In the Linux kernel, the following vulnerability has been resolved: net: fddi: fix UAF in fza_probe fp is netdev private data and it cannot be used after…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net: fddi: fix UAF in fza_probe fp is netdev private data and it cannot be used after free_netdev() call. Using fp after free_netdev() can cause UAF bug. Fix it by moving free_netdev() after error message. TURBOchannel adapter")

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 61414f5ec9834df8aa4f55c90de16b71a3d6ca8d < 04b06716838bfc26742dbed3ae1d3697fe5317ee04b06716838bfc26742dbed3ae1d3697fe5317ee
linuxlinux>= 61414f5ec9834df8aa4f55c90de16b71a3d6ca8d < f33605908a9b6063525e9f68e62d739948c5fccff33605908a9b6063525e9f68e62d739948c5fccf
linuxlinux>= 61414f5ec9834df8aa4f55c90de16b71a3d6ca8d < bdfbb51f7a437ae8ea91317a5c133ec13adf3c47bdfbb51f7a437ae8ea91317a5c133ec13adf3c47
linuxlinux>= 61414f5ec9834df8aa4f55c90de16b71a3d6ca8d < deb7178eb940e2c5caca1b1db084a69b2e59b4c9deb7178eb940e2c5caca1b1db084a69b2e59b4c9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 4.20 < 5.4.1355.4.135
linuxlinux_kernel>= 5.11 < 5.13.55.13.5
linuxlinux_kernel>= 5.5 < 5.10.535.10.53

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.