CVE-2021-3752

CVSS v3.1 7.1 (High)
71% Progress
CVSS v2.0 7.9 (High)
79% Progress
EPSS 0.12 % (47th)
0.12% Progress
Affected Products 27
Advisories 45

A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-02-16 19:15:08
(2 years ago)
Updated Date
2023-11-09 14:44:33
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.12 version and prior 4.4.293 version cpe:2.3:o:linux:linux_kernel >= 2.6.12 < 4.4.293
  Linux Kernel from 4.5 version and prior 4.9.291 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.9.291
  Linux Kernel from 4.10 version and prior 4.14.256 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.256
  Linux Kernel from 4.15 version and prior 4.19.218 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.19.218
  Linux Kernel from 4.20 version and prior 5.4.160 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.4.160
  Linux Kernel from 5.5 version and prior 5.10.80 version cpe:2.3:o:linux:linux_kernel >= 5.5 < 5.10.80
  Linux Kernel from 5.11 version and prior 5.14.19 version cpe:2.3:o:linux:linux_kernel >= 5.11 < 5.14.19
  Linux Kernel from 5.15 version and prior 5.15.3 version cpe:2.3:o:linux:linux_kernel >= 5.15 < 5.15.3

Configuration #2

    CPE23 From Up To
  Redhat 3scale 2.0 cpe:2.3:a:redhat:3scale:2.0
  Redhat Virtualization Host 4.0 cpe:2.3:a:redhat:virtualization_host:4.0
  Fedoraproject Fedora 34 cpe:2.3:o:fedoraproject:fedora:34
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
  Redhat Enterprise Linux for Real Time 7 cpe:2.3:o:redhat:enterprise_linux_for_real_time:7
  Redhat Enterprise Linux for Real Time For Nfv 7 cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:7

Configuration #3

AND
    CPE23 From Up To
OR  
  Netapp H300s cpe:2.3:h:netapp:h300s:-
OR  
  Running on/with
  Netapp H300s Firmware cpe:2.3:o:netapp:h300s_firmware:-

Configuration #4

AND
    CPE23 From Up To
OR  
  Netapp H500s cpe:2.3:h:netapp:h500s:-
OR  
  Running on/with
  Netapp H500s Firmware cpe:2.3:o:netapp:h500s_firmware:-

Configuration #5

AND
    CPE23 From Up To
OR  
  Netapp H700s cpe:2.3:h:netapp:h700s:-
OR  
  Running on/with
  Netapp H700s Firmware cpe:2.3:o:netapp:h700s_firmware:-

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp H300e cpe:2.3:h:netapp:h300e:-
OR  
  Running on/with
  Netapp H300e Firmware cpe:2.3:o:netapp:h300e_firmware:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp H500e cpe:2.3:h:netapp:h500e:-
OR  
  Running on/with
  Netapp H500e Firmware cpe:2.3:o:netapp:h500e_firmware:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp H700e cpe:2.3:h:netapp:h700e:-
OR  
  Running on/with
  Netapp H700e Firmware cpe:2.3:o:netapp:h700e_firmware:-

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H410s cpe:2.3:h:netapp:h410s:-
OR  
  Running on/with
  Netapp H410s Firmware cpe:2.3:o:netapp:h410s_firmware:-

Configuration #10

AND
    CPE23 From Up To
OR  
  Netapp H410c Firmware cpe:2.3:o:netapp:h410c_firmware:-
OR  
  Running on/with
  Netapp H410c cpe:2.3:h:netapp:h410c:-

Configuration #11

    CPE23 From Up To
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #12

    CPE23 From Up To
  Oracle Communications Cloud Native Core Binding Support Function 22.1.3 cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3
  Oracle Communications Cloud Native Core Network Exposure Function 22.1.1 cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.1
  Oracle Communications Cloud Native Core Policy 22.2.0 cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.2.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...