CVE-2021-3659: Null Pointer Dereference

Published Apr 6, 2021
·
Updated

A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.

Other sources

The bug is inside net/mac802154/llsec.c (IEEE 802.15.4 support). If fails allocating of the cipher handle for AEAD during initialization of LR-WPAN, then NULL pointer dereference could happen.

Reference: https://syzkaller.appspot.com/bug?extid=12cf5fbfdeba210a89dd

Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1165affd484889d4986cf3b724318935a0b120d8

The previously used CVE for this one was CVE-2021-33033 (because this issue already incorrectly referenced before from that older CVE).

Red Hat

Affected Software

31 affected componentsFixes available
redhat/kernel-rt<0:4.18.0-348.rt7.130.el8
0:4.18.0-348.rt7.130.el8
redhat/kernel<0:4.18.0-348.el8
0:4.18.0-348.el8
redhat/Kernel<5.12
5.12
Linux Linux kernel<5.12
Fedoraproject Fedora=34
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux For Ibm Z Systems=8.0
redhat Enterprise Linux For Ibm Z Systems Eus=8.6
redhat Enterprise Linux For Power Little Endian Eus=8.6
redhat Enterprise Linux For Real Time=8.0
redhat Enterprise Linux For Real Time For Nfv=8.0
redhat Enterprise Linux For Real Time For Nfv Tus=8.6
redhat Enterprise Linux For Real Time Tus=8.6
redhat Enterprise Linux Server Aus=8.6
redhat Enterprise Linux Server Eus=8.6
redhat Enterprise Linux Server Tus=8.6
All of the following
redhat Codeready Linux Builder
Any of the following
redhat Enterprise Linux=8.0
redhat Enterprise Linux Eus=8.6
redhat Enterprise Linux For Power Little Endian=8.0
redhat Enterprise Linux For Power Little Endian Eus=8.6
All of the following
redhat Virtualization Host=4.0
redhat Enterprise Linux=8.0
redhat Codeready Linux Builder
redhat Enterprise Linux=8.0
redhat Enterprise Linux Eus=8.6
redhat Enterprise Linux For Power Little Endian=8.0
redhat Enterprise Linux For Power Little Endian Eus=8.6
redhat Virtualization Host=4.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1

Remediation

Information

To mitigate this issue, prevent the module mac802154 from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.

Event History

Apr 6, 2021
CVE Published
07:22 PM
Aug 22, 2022
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:58 PM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·04:30 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-3659?

The severity of CVE-2021-3659 is high due to its impact on system availability.

2

How do I fix CVE-2021-3659?

To fix CVE-2021-3659, upgrade to the patched versions of the Linux kernel as specified by your distribution, such as kernel-rt 0:4.18.0-348.rt7.130.el8 or kernel 0:4.18.0-348.el8.

3

What causes CVE-2021-3659?

CVE-2021-3659 is caused by a NULL pointer dereference flaw in the IEEE 802.15.4 wireless networking subsystem of the Linux kernel.

4

Which Linux distributions are affected by CVE-2021-3659?

CVE-2021-3659 affects several Linux distributions including Red Hat Enterprise Linux, Fedora, and Debian.

5

Can CVE-2021-3659 be exploited remotely?

No, CVE-2021-3659 is a local vulnerability that requires local user access to the system to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203