CVE-2021-3483
N/A
N/A
Summary
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | kernel | 0 < 4.4.265 | affected |
| Linux | kernel | 4.5 < 4.9.265 | affected |
| Linux | kernel | 4.10 < 4.14.229 | affected |
| Linux | kernel | 4.15 < 4.19.185 | affected |
| Linux | kernel | 4.20 < 5.4.110 | affected |
| Linux | kernel | 5.5 < 5.10.28 | affected |
| Linux | kernel | 5.11 < 5.11.12 | affected |
Weaknesses
- CWE-416: CWE-416
ADP Enrichment
CVE Program Container
Additional References
- http://www.openwall.com/lists/oss-security/2021/04/07/1
- https://bugzilla.redhat.com/show_bug.cgi?id=1948045
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
- https://security.netapp.com/advisory/ntap-20210629-0002/
References
- http://www.openwall.com/lists/oss-security/2021/04/07/1
- https://bugzilla.redhat.com/show_bug.cgi?id=1948045
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
- https://security.netapp.com/advisory/ntap-20210629-0002/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.