We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2021-47068

net/nfc: fix use-after-free llcp_sock_bind/connect



Description

In the Linux kernel, the following vulnerability has been resolved: net/nfc: fix use-after-free llcp_sock_bind/connect Commits 8a4cd82d ("nfc: fix refcount leak in llcp_sock_connect()") and c33b1cc62 ("nfc: fix refcount leak in llcp_sock_bind()") fixed a refcount leak bug in bind/connect but introduced a use-after-free if the same local is assigned to 2 different sockets. This can be triggered by the following simple program: int sock1 = socket( AF_NFC, SOCK_STREAM, NFC_SOCKPROTO_LLCP ); int sock2 = socket( AF_NFC, SOCK_STREAM, NFC_SOCKPROTO_LLCP ); memset( &addr, 0, sizeof(struct sockaddr_nfc_llcp) ); addr.sa_family = AF_NFC; addr.nfc_protocol = NFC_PROTO_NFC_DEP; bind( sock1, (struct sockaddr*) &addr, sizeof(struct sockaddr_nfc_llcp) ) bind( sock2, (struct sockaddr*) &addr, sizeof(struct sockaddr_nfc_llcp) ) close(sock1); close(sock2); Fix this by assigning NULL to llcp_sock->local after calling nfc_llcp_local_put. This addresses CVE-2021-23134.

Reserved 2024-02-29 | Published 2024-02-29 | Updated 2024-12-19 | Assigner Linux

Product status

Default status
unaffected

a1cdd18c49d23ec38097ac2c5b0d761146fc0109 before 26157c82ba756767b2bd66d28a71b1bc454447f6
affected

18013007b596771bf5f5e7feee9586fb0386ad14 before ccddad6dd28530e716448e594c9ca7c76ccd0570
affected

538a6ff11516d38a61e237d2d2dc04c30c845fbe before 18ae4a192a4496e48a5490b52812645d2413307c
affected

adbb1d218c5f56dbae052765da83c0f57fce2a31 before 48fba458fe54cc2a980a05c13e6c19b8b2cfb610
affected

c89903c9eff219a4695e63715cf922748d743f65 before e32352070bcac22be6ed8ab635debc280bb65b8c
affected

6fb003e5ae18d8cda4c8a1175d9dd8db12bec049 before 6b7021ed36dabf29e56842e3408781cd3b82ef6e
affected

8c9e4971e142e2899606a2490b77a1208c1f4638 before 374cdde4dcc9c909a60713abdbbf96d5e3e09f91
affected

c33b1cc62ac05c1dbb1cdafe2eb66da01c76ca8d before 18175fe17ae043a0b81e5d511f8817825784c299
affected

c33b1cc62ac05c1dbb1cdafe2eb66da01c76ca8d before c61760e6940dd4039a7f5e84a6afc9cdbf4d82b6
affected

Default status
affected

5.12
affected

Any version before 5.12
unaffected

4.4.269
unaffected

4.9.269
unaffected

4.14.233
unaffected

4.19.191
unaffected

5.4.119
unaffected

5.10.37
unaffected

5.11.21
unaffected

5.12.4
unaffected

5.13
unaffected

References

git.kernel.org/...c/26157c82ba756767b2bd66d28a71b1bc454447f6

git.kernel.org/...c/ccddad6dd28530e716448e594c9ca7c76ccd0570

git.kernel.org/...c/18ae4a192a4496e48a5490b52812645d2413307c

git.kernel.org/...c/48fba458fe54cc2a980a05c13e6c19b8b2cfb610

git.kernel.org/...c/e32352070bcac22be6ed8ab635debc280bb65b8c

git.kernel.org/...c/6b7021ed36dabf29e56842e3408781cd3b82ef6e

git.kernel.org/...c/374cdde4dcc9c909a60713abdbbf96d5e3e09f91

git.kernel.org/...c/18175fe17ae043a0b81e5d511f8817825784c299

git.kernel.org/...c/c61760e6940dd4039a7f5e84a6afc9cdbf4d82b6

cve.org (CVE-2021-47068)

nvd.nist.gov (CVE-2021-47068)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2021-47068

Support options

Helpdesk Chat, Email, Knowledgebase