CVE-2021-37159

medium

Description

hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.

References

https://www.spinics.net/lists/linux-usb/msg202228.html

https://security.netapp.com/advisory/ntap-20210819-0003/

https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html

https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html

https://www.oracle.com/security-alerts/cpujul2022.html

Details

Source: MITRE

Published: 2021-07-21

Updated: 2022-07-25

Type: CWE-415

Risk Information

CVSS v2

Base Score: 4.4

Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 6.4

Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 0.5

Severity: MEDIUM