CVE-2021-47232 is a Use-after-Free vulnerability in the Linux kernel's J1939 CAN bus driver. It occurs when a network packet (skb) is used without properly incrementing its reference count, leading to potential memory corruption if the packet is concurrently accessed. This vulnerability has a CVSS score of 8.4 (High), indicating a significant risk. It can be exploited locally with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability of the affected system. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has also received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.4, < 5.4.128CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.46CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.12.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:* | ||
5.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.13:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.