ZeroHour

CVE-2021-3640

PoC
CVSS 3.1
7.0 high
EPSS
<1%p31
Published
()
Modified
Description

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

Vendors
linuxdebianfedoraprojectcanonicalnetapp
Products
linux kernel, debian linux, fedora, ubuntu linux, h300s firmware, h700s firmware, h300e firmware, h500e firmware, h700e firmware, h410s firmware, h410c firmware, h500s firmware
Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.