cbcvebase.
CVE-2021-47520
published 2024-05-24

CVE-2021-47520: In the Linux kernel, the following vulnerability has been resolved: can: pch_can: pch_can_rx_normal: fix use after free After calling netif_receive_skb(skb)…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: can: pch_can: pch_can_rx_normal: fix use after free After calling netif_receive_skb(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is dereferenced just after the call netif_receive_skb(skb). Reordering the lines solves the issue.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= b21d18b51b31a24d17f883b678432fbdee3d5675 < bafe343a885c70dddf358379cf0b2a1c07355d8dbafe343a885c70dddf358379cf0b2a1c07355d8d
linuxlinux>= b21d18b51b31a24d17f883b678432fbdee3d5675 < 3a3c46e2eff0577454860a203be1a8295f4acb763a3c46e2eff0577454860a203be1a8295f4acb76
linuxlinux>= b21d18b51b31a24d17f883b678432fbdee3d5675 < affbad02bf80380a7403885b9fe4a1587d1bb4f3affbad02bf80380a7403885b9fe4a1587d1bb4f3
linuxlinux>= b21d18b51b31a24d17f883b678432fbdee3d5675 < 3e193ef4e0a3f5bf92ede83ef214cb09d01b00aa3e193ef4e0a3f5bf92ede83ef214cb09d01b00aa
linuxlinux>= b21d18b51b31a24d17f883b678432fbdee3d5675 < abb4eff3dcd2e583060082a18a8dbf31f02689d4abb4eff3dcd2e583060082a18a8dbf31f02689d4
linuxlinux>= b21d18b51b31a24d17f883b678432fbdee3d5675 < 703dde112021c93d6e89443c070e7dbd4dea612e703dde112021c93d6e89443c070e7dbd4dea612e
linuxlinux>= b21d18b51b31a24d17f883b678432fbdee3d5675 < 6c73fc931658d8cbc8a1714b326cb31eb71d16a76c73fc931658d8cbc8a1714b326cb31eb71d16a7
linuxlinux>= b21d18b51b31a24d17f883b678432fbdee3d5675 < 94cddf1e9227a171b27292509d59691819c458db94cddf1e9227a171b27292509d59691819c458db
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 2.6.37 < 4.4.2954.4.295
linuxlinux_kernel>= 4.10 < 4.14.2584.14.258
linuxlinux_kernel>= 4.15 < 4.19.2214.19.221
linuxlinux_kernel>= 4.20 < 5.4.1655.4.165
linuxlinux_kernel>= 4.5 < 4.9.2934.9.293
linuxlinux_kernel>= 5.11 < 5.15.85.15.8
linuxlinux_kernel>= 5.5 < 5.10.855.10.85

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.