CVE-2021-3640

Red Hat Security Advisory: kernel security and bug fix update

Description

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

Source: redhat_csaf

Metrics

28.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2024-02-07 16:33 UTC

Included in the same advisory

Show 32 more CVEs