CVE-2021-37159
MEDIUMLinux Kernel < 5.13.4 - Use-After-Free in hso_free_net_device
Title source: llmDescription
hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.
References (8)
Core 8
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=1188601
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210819-0003/
Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Mailing List, Patch, Third Party Advisory
https://www.spinics.net/lists/linux-usb/msg202228.html
Scores
CVSS v3
6.4
EPSS
0.0003
EPSS Percentile
10.3%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-415
CWE-416
Status
published
Products (5)
debian/debian_linux
9.0
linux/linux_kernel
< 5.13.4
oracle/communications_cloud_native_core_binding_support_function
22.1.3
oracle/communications_cloud_native_core_network_exposure_function
22.1.1
oracle/communications_cloud_native_core_policy
22.2.0
Published
Jul 21, 2021
Tracked Since
Feb 18, 2026