CVE Database
/

CVE-2021-3640

Back to search

CVE-2021-3640

Published: Mar 3, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

VendorProductVersions

n/a

kernel

affected
Affects kernel v5.15.3 and prior, Fixed in v5.16-rc1 and above.

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now