---
id: CVE-2021-37159
title: >-
  hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through
  5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED
  state, leading to a use-after-free and a double free.
summary: >-
  hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through
  5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED
  state, leading to a use-after-free and a double free.
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-415
  - CWE-416
vendor: oracle
product: communications_cloud_native_core_binding_support_function
affected:
  - linux_kernel <= 5.13.4
  - debian_linux = 9.0
  - communications_cloud_native_core_binding_support_function = 22.1.3
  - communications_cloud_native_core_network_exposure_function = 22.1.1
  - communications_cloud_native_core_policy = 22.2.0
published: '2021-07-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:11.047'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-37159'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1188601'
    label: cve@mitre.org
  - url: >-
      https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a6ecfb39ba9d7316057cea823b196b734f6b18ca
    label: cve@mitre.org
  - url: >-
      https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dcb713d53e2eadf42b878c12a471e74dc6ed3145
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20210819-0003/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: cve@mitre.org
  - url: 'https://www.spinics.net/lists/linux-usb/msg202228.html'
    label: cve@mitre.org
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1188601'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a6ecfb39ba9d7316057cea823b196b734f6b18ca
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dcb713d53e2eadf42b878c12a471e74dc6ed3145
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210819-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.spinics.net/lists/linux-usb/msg202228.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-37159.json
  - url: 'https://access.redhat.com/security/cve/CVE-2021-37159'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1985353'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2021-37159'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-37159'
  - url: 'https://access.redhat.com/errata/RHSA-2022:1988'
  - url: 'https://access.redhat.com/errata/RHSA-2022:1975'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00391
epssPercentile: 0.31139
ingestedAt: '2026-10-08T23:16:47.322Z'
patched:
  - enterprise_linux_baseos_v_8
  - enterprise_linux_crb_v_8
  - enterprise_linux_nfv_v_8
  - enterprise_linux_rt_v_8
---

## Overview

hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.

## Affected

- `linux_kernel <= 5.13.4`
- `debian_linux = 9.0`
- `communications_cloud_native_core_binding_support_function = 22.1.3`
- `communications_cloud_native_core_network_exposure_function = 22.1.1`
- `communications_cloud_native_core_policy = 22.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2022:1988** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2022-05-10 · [advisory](https://access.redhat.com/errata/RHSA-2022:1988)
- **RHSA-2022:1975** · Red Hat · fixed in: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8) · released 2022-05-10 · [advisory](https://access.redhat.com/errata/RHSA-2022:1975)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9 · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-37159.json)
