---
id: CVE-2021-23134
title: >-
  Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4
  allows local attackers to elevate their privileges
summary: >-
  Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4
  allows local attackers to elevate their privileges. In typical configurations,
  the issue can only be triggered by a privileged local user with the
  CAP_NET_RAW …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
  - CWE-416
vendor: netapp
product: cloud_backup
affected:
  - cloud_backup
  - h300s_firmware
  - h500s_firmware
  - h700s_firmware
  - h410s_firmware
  - h410c_firmware
  - solidfire_baseboard_management_controller_firmware
  - linux_kernel < 4.4.269
  - 'linux_kernel >= 4.5, < 4.9.269'
  - 'linux_kernel >= 4.10, < 4.14.233'
  - 'linux_kernel >= 4.15, < 4.19.191'
  - 'linux_kernel >= 4.20, < 5.4.119'
  - 'linux_kernel >= 5.5, < 5.10.37'
  - 'linux_kernel >= 5.11, < 5.11.21'
  - 'linux_kernel >= 5.12, < 5.12.4'
  - fedora = 33
  - fedora = 34
  - debian_linux = 9.0
patched:
  - linux_kernel 5.12.4
published: '2021-05-12'
updated: '2026-07-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-23134'
references:
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c61760e6940d
    label: psirt@paloaltonetworks.com
  - url: 'https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html'
    label: psirt@paloaltonetworks.com
  - url: 'https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html'
    label: psirt@paloaltonetworks.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZYORWNQIHNWRFYRDXBWYWBYM46PDZEN/
    label: psirt@paloaltonetworks.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QALNQT4LJFVSSA3MWCIECVY4AFPP4X77/
    label: psirt@paloaltonetworks.com
  - url: 'https://security.netapp.com/advisory/ntap-20210625-0007/'
    label: psirt@paloaltonetworks.com
  - url: 'https://www.openwall.com/lists/oss-security/2021/05/11/4'
    label: psirt@paloaltonetworks.com
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c61760e6940d
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZYORWNQIHNWRFYRDXBWYWBYM46PDZEN/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QALNQT4LJFVSSA3MWCIECVY4AFPP4X77/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210625-0007/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2021/05/11/4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00375
epssPercentile: 0.28822
ingestedAt: '2026-07-30T19:55:34.861Z'
---

## Overview

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

## Affected

- `cloud_backup`
- `h300s_firmware`
- `h500s_firmware`
- `h700s_firmware`
- `h410s_firmware`
- `h410c_firmware`
- `solidfire_baseboard_management_controller_firmware`
- `linux_kernel < 4.4.269`
- `linux_kernel >= 4.5, < 4.9.269`
- `linux_kernel >= 4.10, < 4.14.233`
- `linux_kernel >= 4.15, < 4.19.191`
- `linux_kernel >= 4.20, < 5.4.119`
- `linux_kernel >= 5.5, < 5.10.37`
- `linux_kernel >= 5.11, < 5.11.21`
- `linux_kernel >= 5.12, < 5.12.4`
- `fedora = 33`
- `fedora = 34`
- `debian_linux = 9.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.12.4`
