cbcvebase.
CVE-2021-47521
published 2024-05-24

CVE-2021-47521: In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set up.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= fd734c6f25aea4b2b44b045e489aec67b388577e < cbd86110546f7f730a1f5d7de56c944a336c15c4cbd86110546f7f730a1f5d7de56c944a336c15c4
linuxlinux>= fd734c6f25aea4b2b44b045e489aec67b388577e < 1dd5b819f7e406dc15bbc7670596ff25261aaa2a1dd5b819f7e406dc15bbc7670596ff25261aaa2a
linuxlinux>= fd734c6f25aea4b2b44b045e489aec67b388577e < c8718026ba287168ff9ad0ccc4f9a413062cba36c8718026ba287168ff9ad0ccc4f9a413062cba36
linuxlinux>= fd734c6f25aea4b2b44b045e489aec67b388577e < ccf070183e4655824936c0f96c4a2bcca93419aaccf070183e4655824936c0f96c4a2bcca93419aa
linuxlinux>= fd734c6f25aea4b2b44b045e489aec67b388577e < 1a295fea90e1acbe80c6d4940f5ff856edcd6bec1a295fea90e1acbe80c6d4940f5ff856edcd6bec
linuxlinux>= fd734c6f25aea4b2b44b045e489aec67b388577e < 923f4dc5df679f678e121c20bf2fd70f7bf3e288923f4dc5df679f678e121c20bf2fd70f7bf3e288
linuxlinux>= fd734c6f25aea4b2b44b045e489aec67b388577e < 474f9a8534f5f89841240a7e978bafd6e1e039ce474f9a8534f5f89841240a7e978bafd6e1e039ce
linuxlinux>= fd734c6f25aea4b2b44b045e489aec67b388577e < 3ec6ca6b1a8e64389f0212b5a1b0f6fed1909e453ec6ca6b1a8e64389f0212b5a1b0f6fed1909e45
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 4.4.0-258.2924.4.0-258.292
linuxlinux_kernel>= 3.2 < 4.4.2954.4.295
linuxlinux_kernel>= 4.10 < 4.14.2584.14.258
linuxlinux_kernel>= 4.15 < 4.19.2214.19.221
linuxlinux_kernel>= 4.20 < 5.4.1655.4.165
linuxlinux_kernel>= 4.5 < 4.9.2934.9.293
linuxlinux_kernel>= 5.11 < 5.15.85.15.8
linuxlinux_kernel>= 5.5 < 5.10.855.10.85

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.