Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-33034

Опубликовано: 22 мар. 2021
Источник: redhat
CVSS3: 7.8

Описание

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

A use-after-free flaw was found in hci_send_acl in the bluetooth host controller interface (HCI) in Linux kernel, where a local attacker with an access rights could cause a denial of service problem on the system The issue results from the object hchan, freed in hci_disconn_loglink_complete_evt, yet still used in other places. The highest threat from this vulnerability is to data integrity, confidentiality and system availability.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2021:272621.07.2021
Red Hat Enterprise Linux 7kernelFixedRHSA-2021:272521.07.2021
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2021:272720.07.2021
Red Hat Enterprise Linux 7.2 Advanced Update SupportkernelFixedRHSA-2021:273420.07.2021
Red Hat Enterprise Linux 7.3 Advanced Update SupportkernelFixedRHSA-2021:273320.07.2021
Red Hat Enterprise Linux 7.4 Advanced Update SupportkernelFixedRHSA-2021:273220.07.2021
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportkernelFixedRHSA-2021:273220.07.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1961305kernel: use-after-free in net/bluetooth/hci_event.c when destroying an hci_chan

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

CVSS3: 7.8
nvd
около 4 лет назад

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

CVSS3: 7.8
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 4 лет назад

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use ...

CVSS3: 7.8
github
около 3 лет назад

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

7.8 High

CVSS3