Back to bug 2036682

Who When What Removed Added
Pedro Sampaio 2022-01-03 15:06:53 UTC Blocks 2036683
Rohit Keshri 2022-01-07 10:54:58 UTC Doc Text A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux Kernel. This flaw could allow a local attacker with user privilege to cause a data race problem while the device is getting removed, this flaw could lead to a privilege escalation problem.
Rohit Keshri 2022-01-07 10:55:29 UTC Fixed In Version kernel 5.16 rc2
Rohit Keshri 2022-01-07 11:04:20 UTC Depends On 2038123
Rohit Keshri 2022-01-07 12:52:51 UTC Comment 0 updated
Rohit Keshri 2022-01-07 12:53:11 UTC CC rkeshri
Marian Rehak 2022-01-10 13:00:44 UTC Summary kernel: Race condition in nci_request() leads to use after free while the device is getting removed CVE-2021-4202 kernel: Race condition in nci_request() leads to use after free while the device is getting removed
Alias CVE-2021-4202
Marian Rehak 2022-01-10 13:04:17 UTC Blocks 2038882
Eric Christensen 2022-01-10 15:29:38 UTC Doc Text A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux Kernel. This flaw could allow a local attacker with user privilege to cause a data race problem while the device is getting removed, this flaw could lead to a privilege escalation problem. A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege escalation problem.
Rohit Keshri 2022-01-11 09:33:07 UTC Comment 0 updated
Rohit Keshri 2022-01-11 11:36:47 UTC Comment 0 updated
Marcelo Ricardo Leitner 2022-01-13 19:02:50 UTC CC mleitner
Red Hat Bugzilla 2022-06-04 08:05:16 UTC CC fpacheco
Red Hat Bugzilla 2022-07-16 03:21:29 UTC CC brdeoliv
Red Hat Bugzilla 2022-12-31 23:34:30 UTC CC fhrbata
Red Hat Bugzilla 2023-04-01 08:39:32 UTC CC dhoward
Red Hat Bugzilla 2023-07-07 08:35:54 UTC Assignee security-response-team nobody

Back to bug 2036682