CVE-2021-23134
Last modified
CVE-2021-23134 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Cloud Backup | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
| Netapp | H410c Firmware | All versions |
| Netapp | Solidfire Baseboard Management Controller Firmware | All versions |
| Linux | Linux Kernel | < 4.4.269 |
| Linux | Linux Kernel | >= 4.5, < 4.9.269 |
| Linux | Linux Kernel | >= 4.10, < 4.14.233 |
| Linux | Linux Kernel | >= 4.15, < 4.19.191 |
| Linux | Linux Kernel | >= 4.20, < 5.4.119 |
| Linux | Linux Kernel | >= 5.5, < 5.10.37 |
| Linux | Linux Kernel | >= 5.11, < 5.11.21 |
| Linux | Linux Kernel | >= 5.12, < 5.12.4 |
| Fedoraproject | Fedora | 33 |
| Fedoraproject | Fedora | 34 |
| Debian | Debian Linux | 9.0 |
References
- https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c61760e6940dMailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210625-0007/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/05/11/4Mailing List, Patch, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c61760e6940dMailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210625-0007/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/05/11/4Mailing List, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-23134?
How severe is CVE-2021-23134?
How do I fix CVE-2021-23134?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-23128An issue was discovered in Joomla! 3.2.0 through 3.9.24. The…9.1
- CVE-2021-23129An issue was discovered in Joomla! 2.5.0 through 3.9.24. Mis…6.1
- CVE-2021-23130An issue was discovered in Joomla! 2.5.0 through 3.9.24. Mis…6.1
- CVE-2021-23131An issue was discovered in Joomla! 3.2.0 through 3.9.24. Mis…7.5
- CVE-2021-23132An issue was discovered in Joomla! 3.0.0 through 3.9.24. com…7.5
- CVE-2021-23133A race condition in Linux kernel SCTP sockets (net/sctp/sock…7
- CVE-2021-23135Exposure of System Data to an Unauthorized Control Sphere vu…5.5
- CVE-2021-23136Improper Authorization vulnerability in Gallagher Command Ce…6.5
- CVE-2021-23138WECON LeviStudioU Versions 2019-09-21 and prior are vulnerab…7.8
- CVE-2021-23139A null pointer vulnerability in Trend Micro Apex One and Wor…7.5
- CVE-2021-2314Vulnerability in the Oracle Application Object Library produ…8.1
- CVE-2021-23140Improper Authorization vulnerability in Gallagher Command Ce…8.8
Are you affected by CVE-2021-23134?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
