CVE-2021-23134: Linux kernel llcp_sock_bind/connect use-after-free
Last updated 29 November 2024
Other sources
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAPNETRAW capability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23134?
CVE-2021-23134 is classified as a high severity vulnerability that allows local attackers to elevate privileges.
How do I fix CVE-2021-23134?
To fix CVE-2021-23134, update the Linux kernel to version 5.12.4 or later.
Who is affected by CVE-2021-23134?
CVE-2021-23134 affects local users with CAP_NET_RAW capability on Linux kernels prior to version 5.12.4.
What type of vulnerability is CVE-2021-23134?
CVE-2021-23134 is a Use After Free vulnerability found in NFC sockets in the Linux kernel.
Can CVE-2021-23134 be exploited remotely?
CVE-2021-23134 typically requires local access to exploit, making remote exploitation unlikely.