CVE-2021-47521
published 2024-05-24CVE-2021-47521: In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
can: sja1000: fix use after free in ems_pcmcia_add_card()
If the last channel is not available then "dev" is freed. Fortunately,
we can just use "pdev->irq" instead.
Also we should check if at least one channel was set up.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= fd734c6f25aea4b2b44b045e489aec67b388577e < cbd86110546f7f730a1f5d7de56c944a336c15c4 | cbd86110546f7f730a1f5d7de56c944a336c15c4 |
| linux | linux | >= fd734c6f25aea4b2b44b045e489aec67b388577e < 1dd5b819f7e406dc15bbc7670596ff25261aaa2a | 1dd5b819f7e406dc15bbc7670596ff25261aaa2a |
| linux | linux | >= fd734c6f25aea4b2b44b045e489aec67b388577e < c8718026ba287168ff9ad0ccc4f9a413062cba36 | c8718026ba287168ff9ad0ccc4f9a413062cba36 |
| linux | linux | >= fd734c6f25aea4b2b44b045e489aec67b388577e < ccf070183e4655824936c0f96c4a2bcca93419aa | ccf070183e4655824936c0f96c4a2bcca93419aa |
| linux | linux | >= fd734c6f25aea4b2b44b045e489aec67b388577e < 1a295fea90e1acbe80c6d4940f5ff856edcd6bec | 1a295fea90e1acbe80c6d4940f5ff856edcd6bec |
| linux | linux | >= fd734c6f25aea4b2b44b045e489aec67b388577e < 923f4dc5df679f678e121c20bf2fd70f7bf3e288 | 923f4dc5df679f678e121c20bf2fd70f7bf3e288 |
| linux | linux | >= fd734c6f25aea4b2b44b045e489aec67b388577e < 474f9a8534f5f89841240a7e978bafd6e1e039ce | 474f9a8534f5f89841240a7e978bafd6e1e039ce |
| linux | linux | >= fd734c6f25aea4b2b44b045e489aec67b388577e < 3ec6ca6b1a8e64389f0212b5a1b0f6fed1909e45 | 3ec6ca6b1a8e64389f0212b5a1b0f6fed1909e45 |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 4.4.0-258.292 | 4.4.0-258.292 |
| linux | linux_kernel | >= 3.2 < 4.4.295 | 4.4.295 |
| linux | linux_kernel | >= 4.10 < 4.14.258 | 4.14.258 |
| linux | linux_kernel | >= 4.15 < 4.19.221 | 4.19.221 |
| linux | linux_kernel | >= 4.20 < 5.4.165 | 5.4.165 |
| linux | linux_kernel | >= 4.5 < 4.9.293 | 4.9.293 |
| linux | linux_kernel | >= 5.11 < 5.15.8 | 5.15.8 |
| linux | linux_kernel | >= 5.5 < 5.10.85 | 5.10.85 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: can: sja1000: fix use after free in ems_pcmcia_add_card()
vendor_redhat·2024-05-24·CVSS 7.8
CVE-2021-47521 [HIGH] CWE-416 kernel: can: sja1000: fix use after free in ems_pcmcia_add_card()
kernel: can: sja1000: fix use after free in ems_pcmcia_add_card()
In the Linux kernel, the following vulnerability has been resolved:
can: sja1000: fix use after free in ems_pcmcia_add_card()
If the last channel is not available then "dev" is freed. Fortunately,
we can just use "pdev->irq" instead.
Also we should check if at least one channel was set up.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-47521: linux - In the Linux kernel, the following vulnerability has been resolved: can: sja100...
vendor_debian·2021·CVSS 7.8
CVE-2021-47521 [HIGH] CVE-2021-47521: linux - In the Linux kernel, the following vulnerability has been resolved: can: sja100...
In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set up.
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.92-1)
forky: resolved (fixed in 5.15.15-1)
sid: resolved (fixed in 5.15.15-1)
trixie: resolved (fixed in 5.15.15-1)
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-08-21·CVSS 5.5
CVE-2024-22099 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Yuxuan Hu discovered that the Bluetooth RFCOMM protocol driver in the Linux
Kernel contained a race condition, leading to a NULL pointer dereference.
An attacker could possibly use this to cause a denial of service (system
crash). (CVE-2024-22099)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- User-Mode Linu
OSV
CVE-2021-47521: In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is n
osv·2024-05-24·CVSS 7.8
CVE-2021-47521 [HIGH] CVE-2021-47521: In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is n
In the Linux kernel, the following vulnerability has been resolved: can: sja1000: fix use after free in ems_pcmcia_add_card() If the last channel is not available then "dev" is freed. Fortunately, we can just use "pdev->irq" instead. Also we should check if at least one channel was set up.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1a295fea90e1acbe80c6d4940f5ff856edcd6bechttps://git.kernel.org/stable/c/1dd5b819f7e406dc15bbc7670596ff25261aaa2ahttps://git.kernel.org/stable/c/3ec6ca6b1a8e64389f0212b5a1b0f6fed1909e45https://git.kernel.org/stable/c/474f9a8534f5f89841240a7e978bafd6e1e039cehttps://git.kernel.org/stable/c/923f4dc5df679f678e121c20bf2fd70f7bf3e288https://git.kernel.org/stable/c/c8718026ba287168ff9ad0ccc4f9a413062cba36https://git.kernel.org/stable/c/cbd86110546f7f730a1f5d7de56c944a336c15c4https://git.kernel.org/stable/c/ccf070183e4655824936c0f96c4a2bcca93419aahttps://git.kernel.org/stable/c/1a295fea90e1acbe80c6d4940f5ff856edcd6bechttps://git.kernel.org/stable/c/1dd5b819f7e406dc15bbc7670596ff25261aaa2ahttps://git.kernel.org/stable/c/3ec6ca6b1a8e64389f0212b5a1b0f6fed1909e45https://git.kernel.org/stable/c/474f9a8534f5f89841240a7e978bafd6e1e039cehttps://git.kernel.org/stable/c/923f4dc5df679f678e121c20bf2fd70f7bf3e288https://git.kernel.org/stable/c/c8718026ba287168ff9ad0ccc4f9a413062cba36https://git.kernel.org/stable/c/cbd86110546f7f730a1f5d7de56c944a336c15c4https://git.kernel.org/stable/c/ccf070183e4655824936c0f96c4a2bcca93419aa
2024-05-24
Published