cbcvebase.
CVE-2021-47311
published 2024-05-21

CVE-2021-47311: In the Linux kernel, the following vulnerability has been resolved: net: qcom/emac: fix UAF in emac_remove adpt is netdev private data and it cannot be used…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net: qcom/emac: fix UAF in emac_remove adpt is netdev private data and it cannot be used after free_netdev() call. Using adpt after free_netdev() can cause UAF bug. Fix it by moving free_netdev() at the end of the function.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 54e19bc74f3380d414681762ceed9f7245bc6a6e < 4d04a42b926e682140776e54188f4a44f1f01a814d04a42b926e682140776e54188f4a44f1f01a81
linuxlinux>= 54e19bc74f3380d414681762ceed9f7245bc6a6e < b1e091331920f8fbfc747dcbd16263fcd71abb2db1e091331920f8fbfc747dcbd16263fcd71abb2d
linuxlinux>= 54e19bc74f3380d414681762ceed9f7245bc6a6e < 11e9d163d631198bb3eb41a677a61b499516c0f711e9d163d631198bb3eb41a677a61b499516c0f7
linuxlinux>= 54e19bc74f3380d414681762ceed9f7245bc6a6e < 2b70ca92847c619d6264c7372ef74fcbfd1e048c2b70ca92847c619d6264c7372ef74fcbfd1e048c
linuxlinux>= 54e19bc74f3380d414681762ceed9f7245bc6a6e < b560521eca03d0a2db6093a5a632cbdd0a0cf833b560521eca03d0a2db6093a5a632cbdd0a0cf833
linuxlinux>= 54e19bc74f3380d414681762ceed9f7245bc6a6e < 8a225a6e07a57a1538d53637cb3d82bd3e4778398a225a6e07a57a1538d53637cb3d82bd3e477839
linuxlinux>= 54e19bc74f3380d414681762ceed9f7245bc6a6e < ad297cd2db8953e2202970e9504cab247b6c7cb4ad297cd2db8953e2202970e9504cab247b6c7cb4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 4.10 < 4.14.2414.14.241
linuxlinux_kernel>= 4.15 < 4.19.1994.19.199
linuxlinux_kernel>= 4.20 < 5.4.1355.4.135
linuxlinux_kernel>= 4.9 < 4.9.2774.9.277
linuxlinux_kernel>= 5.11 < 5.13.55.13.5
linuxlinux_kernel>= 5.5 < 5.10.535.10.53

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.