Description
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- debian / debian_linux9.0 – 9.0
- Linux / Kernel4.15 – 4.19.185
- Linux / Kernel4.20 – 5.4.110
- Linux / Kernel0 – 4.4.265
- Linux / Kernel5.5 – 5.10.28
- Linux / Kernel5.11 – 5.11.12
- Linux / Kernel4.10 – 4.14.229
- Linux / Kernel4.5 – 4.9.265
- Linux / Linux kernel5.12 – 5.12
- Linux / Linux kernel5.12
- Linux / Linux kernel5.12 – 5.12
- Linux / Linux kernel5.12 – 5.12
- Linux / Linux kernel5.12 – 5.12
- Linux / Linux kernel5.12 – 5.12
- NETAPP / cloud_backup
- NETAPP / h300e_firmware
- NETAPP / h300s_firmware
- NETAPP / h410c_firmware
- NETAPP / h410s_firmware
- NETAPP / h500e_firmware
- NETAPP / h500s_firmware
- NETAPP / h700e_firmware
- NETAPP / h700s_firmware
References
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2021/04/07/1
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=1948045
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2021/06/msg00020.html
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
- MISChttps://security.netapp.com/advisory/ntap-20210629-0002/
Updated 4m ago · 8 sources