cbcvebase.
CVE-2021-47668
published 2025-04-17

CVE-2021-47668: In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the netif_rx_ni() in: stats->rx_bytes += cf->len; Reordering the lines solves the issue.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.12-1 (bookworm)linux 5.10.12-1 (bookworm)
linuxlinux
linuxlinux>= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 260925a0b7d2da5449f8ecfd02c1405e0c8a45b8260925a0b7d2da5449f8ecfd02c1405e0c8a45b8
linuxlinux>= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < bbc6847b9b8978b520f62fbc7c68c54ef0f8d282bbc6847b9b8978b520f62fbc7c68c54ef0f8d282
linuxlinux>= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 92668d28c7e6a7a2ba07df287669ffcdf650c42192668d28c7e6a7a2ba07df287669ffcdf650c421
linuxlinux>= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 08ab951787098ae0b6c0364aeea7a8138226f23408ab951787098ae0b6c0364aeea7a8138226f234
linuxlinux>= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < ac48ef15826e83f4206c47add61072e8fc76d328ac48ef15826e83f4206c47add61072e8fc76d328
linuxlinux>= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 593c072b7b3c4d7044416eb039d9ad706bedd67a593c072b7b3c4d7044416eb039d9ad706bedd67a
linuxlinux>= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 03f16c5075b22c8902d2af739969e878b0879c9403f16c5075b22c8902d2af739969e878b0879c94
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.12-15.10.12-1
linuxlinux_kernel>= 0 < 5.10.12-15.10.12-1
linuxlinux_kernel>= 0 < 5.10.12-15.10.12-1
linuxlinux_kernel>= 0 < 5.10.12-15.10.12-1
linuxlinux_kernel>= 2.6.31 < 4.4.2544.4.254
linuxlinux_kernel>= 4.10 < 4.14.2184.14.218
linuxlinux_kernel>= 4.15 < 4.19.1714.19.171
linuxlinux_kernel>= 4.20 < 5.4.935.4.93
linuxlinux_kernel>= 4.5 < 4.9.2544.9.254
linuxlinux_kernel>= 5.5 < 5.10.115.10.11

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.