7.8highHigh

CVE-2021-33034

Linux Linux Kernel

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

Exploitation status

  • Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.8 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-416
Assigned by
cve@mitre.org

Dates

Published
2021-05-14
Last modified
2026-08-13
Sources
NVD

Affected products

  • Linux Linux Kernel- 4.4.269, 4.5 - 4.9.269, 4.10 - 4.14.233, 4.15 - 4.19.191, 4.20 - 5.4.119, 5.5 - 5.10.37, 5.11 - 5.11.21, 5.12 - 5.12.4
  • Fedoraproject Fedora34
  • Debian Debian Linux9.0

As listed in the NVD configuration data. Not a statement about your estate.

References