
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-37159 affects the Linux kernel through version 5.13.4, specifically in the hso_free_net_device function in drivers/net/usb/hso.c. The vulnerability was discovered in July 2021 and involves the driver calling unregister_netdev without checking for the NETREG_REGISTERED state, which can lead to a use-after-free and double free condition (NVD, Debian).
The vulnerability exists in the Option USB High Speed Mobile device driver (hso) in the Linux kernel. The issue occurs when hso_free_net_device calls unregister_netdev without properly checking if the device was previously registered, leading to potential use-after-free and double free conditions. The vulnerability has a CVSS v3.1 base score of 6.4 (Medium) with vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).
A physically proximate attacker with the ability to plug in USB devices could exploit this vulnerability to cause a denial of service (system crash or memory corruption) or potentially execute arbitrary code (Ubuntu).
The vulnerability requires physical access to the system and the ability to connect USB devices. It has been confirmed as exploitable through USB device manipulation, though no public exploits have been observed in the wild (NVD).
The issue has been fixed through two main commits: a6ecfb39ba9d7316057c ("usb: hso: fix error handling code of hso_create_net_device") and dcb713d53e2eadf42b878c12a471e74dc6ed3145 ("usb: hso: remove the bailout parameter"). These patches refactor the error handling code of hso_create_net_device and remove the unnecessary bailout parameter (Kernel Commit, SUSE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."