CVE-2021-3483

Summary

A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected

Affected Software

VendorProductVersion RangeStatus
Linuxkernel0 < 4.4.265affected
Linuxkernel4.5 < 4.9.265affected
Linuxkernel4.10 < 4.14.229affected
Linuxkernel4.15 < 4.19.185affected
Linuxkernel4.20 < 5.4.110affected
Linuxkernel5.5 < 5.10.28affected
Linuxkernel5.11 < 5.11.12affected

Weaknesses

  • CWE-416: CWE-416

ADP Enrichment

CVE Program Container

Additional References

References