CVE-2021-23134 - CVE House
Back to Database
Status published High CVE-2021-23134

Linux kernel llcp_sock_bind/connect use-after-free

Vulnerability Description

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-23134

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Nadav Markus from Palo Alto Networks
  • Or Cohen from Palo Alto Networks

Affected Vendor

Linux Kernel

View all reports →

Affected Software

Linux Kernel
Vulnerable Versions:
unspecified

Timeline

Official Publish: May 12th, 2021
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)