imPC@ndo IT

Tracker / CVE-2021-4202

CVE-2021-4202

High 7.0

A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege escalation problem.

Affected products and versions

linux linux_kernel · 3.2 → 4.4.294
linux linux_kernel · 4.10 → 4.14.257
linux linux_kernel · 4.15 → 4.19.219
linux linux_kernel · 4.20 → 5.4.163
linux linux_kernel · 4.5 → 4.9.292
linux linux_kernel · 5.11 → 5.15.5
linux linux_kernel · 5.5.0 → 5.10.82

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References