Bug 1968057 (CVE-2021-3587) - CVE-2021-3587 kernel: nfc: Null pointer dereference in llcp_sock_getname
Summary: CVE-2021-3587 kernel: nfc: Null pointer dereference in llcp_sock_getname
Keywords:
Status: CLOSED DUPLICATE of bug 1992810
Alias: CVE-2021-3587
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1969289 1969674
Blocks: 1968059 1968758
TreeView+ depends on / blocked
 
Reported: 2021-06-04 19:45 UTC by Pedro Sampaio
Modified: 2022-04-17 21:26 UTC (History)
43 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the Linux kernel. A null pointer dereference in llcp_sock_getname in net/nfc/llcp_sock.c can lead to an unprivileged user triggering this bug, causing denial of service.
Clone Of:
Environment:
Last Closed: 2021-08-24 14:48:28 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2021-06-04 19:45:53 UTC
There is a null pointer dereference in llcp_sock_getname in net/nfc/llcp_sock.c reproduced in linux-5.13.0-rc2. An unprivileged user can trigger this bug and cause denial of service.

References:

https://seclists.org/oss-sec/2021/q2/177
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=4ac06a1e013c

Comment 2 Wade Mealing 2021-06-08 07:07:43 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1969289]

Comment 10 Petr Matousek 2021-08-24 14:48:28 UTC

*** This bug has been marked as a duplicate of bug 1992810 ***

Comment 11 Wade Mealing 2021-08-25 04:47:04 UTC
For anyone following along, this was a duplicate of: CVE-2021-38208


Note You need to log in before you can comment on or make changes to this bug.