Related Vulnerabilities: CVE-2021-3760  

A use-after-free vulnerability of ndev->rf_conn_info object has been found in the Linux kernel NFC stack. The root cause is that ndev->rf_conn_info is forgotten to be set to NULL when the object is released.

Severity Medium

Remote No

Type Arbitrary code execution

Description

A use-after-free vulnerability of ndev->rf_conn_info object has been found in the Linux kernel NFC stack. The root cause is that ndev->rf_conn_info is forgotten to be set to NULL when the object is released.

AVG-1881 linux-hardened 5.14.14.hardened1-1 Medium Vulnerable

AVG-1880 linux-zen 5.14.14.zen1-1 Medium Vulnerable

AVG-1879 linux 5.14.14.arch4-1 Medium Vulnerable

AVG-1741 linux-lts 5.10.75-1 Medium Vulnerable

https://www.openwall.com/lists/oss-security/2021/10/26/2
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1b1499a817c90fd1ce9453a2c98d2a01cca0e775