CVE-2021-4202

Updated: 2025-08-20 02:22:58.449001

Description:

A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege escalation problem.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.9
CVSS Version 3.x HIGH 7.0

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.0 HIGH Not Vulnerable 2024-01-29 08:43:00
CentOS 6 ELS kernel 2.6.32 7.0 HIGH Not Vulnerable 2022-04-13 09:59:56
CentOS 7 ELS kernel 3.10.0 7.0 HIGH Not Vulnerable 2024-07-01 10:21:33
CentOS 8.4 ELS kernel 4.18.0 7.0 HIGH Not Vulnerable 2022-04-27 10:19:39
CentOS 8.5 ELS kernel 4.18.0 7.0 HIGH Not Vulnerable 2022-04-27 10:19:39
CloudLinux 6 ELS kernel 2.6.32 7.0 HIGH Not Vulnerable 2022-12-02 20:03:42
Oracle Linux 6 ELS kernel 2.6.32 7.0 HIGH Not Vulnerable 2022-12-02 20:03:42
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.0 HIGH Already Fixed 2022-10-05 03:15:02
Ubuntu 16.04 ELS linux 4.4.0 7.0 HIGH Released CLSA-2022:1649869212 2022-04-13 13:16:42
Ubuntu 18.04 ELS linux 4.15.0 7.0 HIGH Already Fixed 2023-06-02 09:10:30