CVE-2021-33034: Use After Free
A use-after-free flaw was found in hcisendacl in the bluetooth host controller interface (HCI) in Linux kernel, where a local attacker with an access rights could cause a denial of service problem on the system The issue results from the object hchan, freed in hcidisconnloglinkcompleteevt, yet still used in other places. The highest threat from this vulnerability is to data integrity, confidentiality and system availability.
Other sources
In the Linux kernel before 5.12.4, net/bluetooth/hcievent.c has a use-after-free when destroying an hcichan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a use-after-free flaw when destroying an hcichan in net/bluetooth/hcievent.c. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
— IBM
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2021:2726
- RHSA-2021:2725
- RHSA-2021:2727
- RHSA-2021:2734
- RHSA-2021:2733
- RHSA-2021:2732
- RHSA-2021:2730
- RHSA-2021:2731
- RHSA-2021:2728
- RHSA-2021:2729
- RHSA-2021:2599
- RHSA-2021:2563
- RHSA-2021:2570
- RHSA-2021:2666
- RHSA-2021:2668
- RHSA-2021:2719
- RHSA-2021:2718
- RHSA-2021:2720
- RHBA-2021:2854
- RHSA-2021:2737
- RHSA-2021:2736
- IBM-6497499
Frequently Asked Questions
What is the severity of CVE-2021-33034?
CVE-2021-33034 is classified as a high severity vulnerability that may lead to a denial of service.
How do I fix CVE-2021-33034?
To fix CVE-2021-33034, update to the patched kernel versions specified in the advisory.
What types of systems are affected by CVE-2021-33034?
CVE-2021-33034 affects various Linux kernel versions and distributions, particularly those using Red Hat and Debian.
Can CVE-2021-33034 be exploited remotely?
CVE-2021-33034 requires local access to the system for exploitation, limiting its impact.
What are the potential impacts of CVE-2021-33034?
The potential impact of CVE-2021-33034 includes system crashes and interruptions in service due to denial of service.