CVE-2021-42008: High severity Linux Linux kernel vulnerability
Last updated 25 April 2025
Other sources
The decodedata function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAPNETADMIN capability can lead to root access.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
Linux kernel (drivers/net/hamradio/6pack.c)to a version that resolves this vulnerability.Fixed in 5.13.13
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42008?
CVE-2021-42008 is classified as a critical vulnerability because it allows for a slab out-of-bounds write that can lead to root access.
How do I fix CVE-2021-42008?
To fix CVE-2021-42008, upgrade the Linux kernel to version 5.13.13 or later.
Which versions of the Linux kernel are affected by CVE-2021-42008?
CVE-2021-42008 affects Linux kernel versions prior to 5.13.13.
What are the potential impacts of CVE-2021-42008?
The potential impacts of CVE-2021-42008 include unauthorized root access and system compromise.
Who can exploit CVE-2021-42008?
CVE-2021-42008 can be exploited by any process with the CAP_NET_ADMIN capability.