CVE-2021-3573 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A use after free vulnerability has been found in the hci_sock_bound_ioctl() function of the Linux kernel. It can allow attackers to corrupt kernel heaps (kmalloc-8k to be specific) and adopt further exploitations.
Group Package Affected Fixed Severity Status Ticket
AVG-2066 linux-lts 5.10.42-1 5.10.43-1 Medium Fixed
AVG-2065 linux-hardened 5.12.9.hardened1-1 5.12.10.hardened1-1 Medium Fixed
AVG-2064 linux-zen 5.12.9.zen1-1 5.12.10.zen1-1 Medium Fixed
AVG-2063 linux 5.12.9.arch1-1 5.12.10.arch1-1 Medium Fixed
References
https://www.openwall.com/lists/oss-security/2021/06/08/2
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.10&id=7422eadcf201f2e25eb45b46ffc900fc4214e14f
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.43&id=74caf718cc7422a957aac381c73d798c0a999a65