CVE-2021-23134High· 7.8▾ TwilightUse After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 30.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.4%
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
cloud_backuph300s_firmwareh500s_firmwareh700s_firmwareh410s_firmwareh410c_firmwaresolidfire_baseboard_management_controller_firmwarelinux_kernel < 4.4.269linux_kernel >= 4.5, < 4.9.269linux_kernel >= 4.10, < 4.14.233linux_kernel >= 4.15, < 4.19.191linux_kernel >= 4.20, < 5.4.119linux_kernel >= 5.5, < 5.10.37linux_kernel >= 5.11, < 5.11.21linux_kernel >= 5.12, < 5.12.4fedora = 33fedora = 34debian_linux = 9.0Upgrade past the affected range:
linux_kernel 5.12.4Connected by shared product, vendor, weakness, or advisory.
CVE-2021-3483High· 7.8A flaw was found in the Nosy driver in the Linux kernel
CVE-2021-23133Medium· 6.7A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process
CVE-2021-3506High· 7.1An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4
CVE-2021-33034High· 7.8In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409
CVE-2024-1086High· 7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
CVE-2022-1199High· 7.5A flaw was found in the Linux kernel