hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.
2021-07-21T15:16:20.777
2024-11-21T06:14:45.313
Modified
CVSSv3.1: 6.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | ≤ 5.13.4 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Application | oracle | communications_cloud_native_core_binding_support_function | 22.1.3 | Yes |
Application | oracle | communications_cloud_native_core_network_exposure_function | 22.1.1 | Yes |
Application | oracle | communications_cloud_native_core_policy | 22.2.0 | Yes |