CVE-2021-43976: Medium severity linux kernel vulnerability
A denial of service flaw was found in mwifiexusbrecv in drivers/net/wireless/marvell/mwifiex/usb.c in the usb subsystem of the Linux kernel. This is due to a missing clean-up for a malfunctioning usb device with an unknown recvtype.
Other sources
A denial-of-service flaw was found in mwifiexusbrecv in drivers/net/wireless/marvell/mwifiex/usb.c in the usb subsystem, due to a missing clean-up for a malfunctioning usb device with an unknown recvtype.
Reference and upstream patch: https://patchwork.kernel.org/project/linux-wireless/patch/YX4CqjfRcTa6bVL+@Zekuns-MBP-16.fios-router.home/
— Red Hat
In the Linux kernel through 5.15.2, mwifiexusbrecv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skboverpanic).
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-43976?
CVE-2021-43976 is classified as a denial-of-service vulnerability that can lead to system disruption.
How do I fix CVE-2021-43976?
To fix CVE-2021-43976, update your kernel to version 0:4.18.0-372.9.1.rt7.166.el8 or 0:4.18.0-372.9.1.el8 for Red Hat systems.
What versions of the Linux kernel are affected by CVE-2021-43976?
CVE-2021-43976 affects versions of the Linux kernel up to and including 5.15.2.
Is CVE-2021-43976 present in Debian distributions?
Yes, CVE-2021-43976 is present in Debian Linux versions 9, 10, and 11.
Can CVE-2021-43976 impact network services?
Yes, CVE-2021-43976 can impact network services by causing a denial-of-service due to a malfunctioning USB device.