UBUNTU-CVE-2021-23134

Advisory lineage Upstream: 1 Downstream: 6
Published: 12 May 2021, 23:15
Last modified:20 May 2026, 16:05

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
3.1 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 May 2021, 23:15
Published
Vulnerability first disclosed
20 May 2026, 16:05
Last Modified
Vulnerability information updated

Description

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Systems

  • ubuntulinux

    < 4.15.0-151.157 | < 5.4.0-77.86

  • ubuntulinux-aws

    < 4.15.0-1109.116 | < 5.4.0-1051.53

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1051.53~18.04.1

  • ubuntulinux-aws-5.8

    < 5.8.0-1041.43~20.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2051.53

  • ubuntulinux-aws-hwe

    < 4.15.0-1109.116~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1121.134~14.04.1 | < 4.15.0-1121.134~16.04.1 | all | < 5.4.0-1051.53

  • ubuntulinux-azure-4.15

    < 4.15.0-1121.134

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1051.53~18.04.1

  • ubuntulinux-azure-5.8

    < 5.8.0-1039.42~20.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2033.37

  • ubuntulinux-bluefield

    < 5.4.0-1013.16

  • ubuntulinux-dell300x

    < 4.15.0-1027.32

  • ubuntulinux-fips

    < 4.15.0-1066.75 | < 5.4.0-1028.32

  • ubuntulinux-gcp

    < 4.15.0-1106.120~16.04.1 | all | < 5.4.0-1046.49

  • ubuntulinux-gcp-4.15

    < 4.15.0-1106.120

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1046.49~18.04.1

  • ubuntulinux-gcp-5.8

    < 5.8.0-1038.40~20.04.1

  • ubuntulinux-gcp-edge

    all

  • ubuntulinux-gcp-fips

    < 4.15.0-2016.18

  • ubuntulinux-gke

    < 5.4.0-1046.48

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    < 5.4.0-1046.48~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1018.19

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1018.19~18.04.1

  • ubuntulinux-hwe

    < 4.15.0-151.157~16.04.1 | all

  • ubuntulinux-hwe-5.4

    < 5.4.0-77.86~18.04.1

  • ubuntulinux-hwe-5.8

    < 5.8.0-63.71~20.04.1

  • ubuntulinux-hwe-edge

    all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    < 4.15.0-1097.99 | < 5.4.0-1041.42

  • ubuntulinux-oem

    all

  • ubuntulinux-oem-5.10

    < 5.10.0-1032.33

  • ubuntulinux-oracle

    < 4.15.0-1078.86~16.04.1 | < 4.15.0-1078.86 | < 5.4.0-1048.52

  • ubuntulinux-oracle-5.0

    all

  • ubuntulinux-oracle-5.3

    all

  • ubuntulinux-oracle-5.4

    < 5.4.0-1048.52~18.04.1

  • ubuntulinux-oracle-5.8

    < 5.8.0-1037.38~20.04.1

  • ubuntulinux-raspi

    < 5.4.0-1038.41

  • ubuntulinux-raspi-5.4

    < 5.4.0-1038.41~18.04.1

  • ubuntulinux-raspi-realtime

    all

  • ubuntulinux-raspi2

    < 4.15.0-1092.98 | all

  • ubuntulinux-realtime

    all

  • ubuntulinux-riscv

    all

  • ubuntulinux-riscv-5.8

    all

Showing first 50 affected entries in server-rendered view.

References (11)