CVE Database
/

CVE-2021-47670

Back to search

CVE-2021-47670

Published: Apr 17, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the peak_usb_netif_rx_ni(). Reordering the lines solves the issue.

VendorProductVersions

Linux

Linux

affected
0a25e1f4f18566b750ebd3ae995af64e23111e63 - < 5408824636fa0dfedb9ecb0d94abd573131bfbbe
affected
0a25e1f4f18566b750ebd3ae995af64e23111e63 - < ddd1416f44130377798c1430b76503513b7497c2
affected
0a25e1f4f18566b750ebd3ae995af64e23111e63 - < ec939c13c3fff2114479769c8380b7f1a54feca9
affected
0a25e1f4f18566b750ebd3ae995af64e23111e63 - < 50aca891d7a554db0901b245167cd653d73aaa71

Linux

Linux

affected
4.0
unaffected
0 - < 4.0
unaffected
4.19.171 - <= 4.19.*
unaffected
5.4.93 - <= 5.4.*
unaffected
5.10.11 - <= 5.10.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now