{"id":"CVE-2021-37159","title":"hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.","summary":"hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-415","CWE-416"],"vendor":"oracle","product":"communications_cloud_native_core_binding_support_function","affected":["linux_kernel <= 5.13.4","debian_linux = 9.0","communications_cloud_native_core_binding_support_function = 22.1.3","communications_cloud_native_core_network_exposure_function = 22.1.1","communications_cloud_native_core_policy = 22.2.0"],"published":"2021-07-21","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:11.047","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-37159","references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1188601","label":"cve@mitre.org"},{"url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a6ecfb39ba9d7316057cea823b196b734f6b18ca","label":"cve@mitre.org"},{"url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dcb713d53e2eadf42b878c12a471e74dc6ed3145","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20210819-0003/","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"cve@mitre.org"},{"url":"https://www.spinics.net/lists/linux-usb/msg202228.html","label":"cve@mitre.org"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1188601","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a6ecfb39ba9d7316057cea823b196b734f6b18ca","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dcb713d53e2eadf42b878c12a471e74dc6ed3145","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210819-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.spinics.net/lists/linux-usb/msg202228.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-37159.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-37159"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1985353"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-37159"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-37159"},{"url":"https://access.redhat.com/errata/RHSA-2022:1988"},{"url":"https://access.redhat.com/errata/RHSA-2022:1975"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00391,"epssPercentile":0.31139,"ingestedAt":"2026-10-08T23:16:47.322Z","patched":["enterprise_linux_baseos_v_8","enterprise_linux_crb_v_8","enterprise_linux_nfv_v_8","enterprise_linux_rt_v_8"],"slug":"CVE-2021-37159","body":"## Overview\n\nhso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.\n\n## Affected\n\n- `linux_kernel <= 5.13.4`\n- `debian_linux = 9.0`\n- `communications_cloud_native_core_binding_support_function = 22.1.3`\n- `communications_cloud_native_core_network_exposure_function = 22.1.1`\n- `communications_cloud_native_core_policy = 22.2.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2022:1988** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2022-05-10 · [advisory](https://access.redhat.com/errata/RHSA-2022:1988)\n- **RHSA-2022:1975** · Red Hat · fixed in: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8) · released 2022-05-10 · [advisory](https://access.redhat.com/errata/RHSA-2022:1975)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9 · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-37159.json)","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}