Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-37159 Details

Description

hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://bugzilla.suse.com/show_bug.cgi?id=1188601 CVE
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a6ecfb39ba9d7316057cea823b196b734f6b18ca CVE
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dcb713d53e2eadf42b878c12a471e74dc6ed3145 CVE
https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html CVEMailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html CVEMailing ListThird Party Advisory

see all 16 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-415Double Free[email protected]
CWE-416Use After Free[email protected]

Affected Products

ProductVersions
linux linux kernel
<= 5.13.4

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
debian debian linux
9.0

CPE

  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
oracle communications cloud native core binding support function
22.1.3

CPE

  • cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
oracle communications cloud native core network exposure function
22.1.1

CPE

  • cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
oracle communications cloud native core policy
22.2.0

CPE

  • cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.2.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

14 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-37159
NVD Published Date:
Jul 21, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2021-37159 Details - Not Deferred