CVE-2021-37159
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-37159 affects the Linux kernel through version 5.13.4, specifically in the hso_free_net_device function in drivers/net/usb/hso.c. The vulnerability was discovered in July 2021 and involves the driver calling unregister_netdev without checking for the NETREG_REGISTERED state, which can lead to a use-after-free and double free condition (NVD, Debian).

Technical details

The vulnerability exists in the Option USB High Speed Mobile device driver (hso) in the Linux kernel. The issue occurs when hso_free_net_device calls unregister_netdev without properly checking if the device was previously registered, leading to potential use-after-free and double free conditions. The vulnerability has a CVSS v3.1 base score of 6.4 (Medium) with vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

A physically proximate attacker with the ability to plug in USB devices could exploit this vulnerability to cause a denial of service (system crash or memory corruption) or potentially execute arbitrary code (Ubuntu).

Exploitability

The vulnerability requires physical access to the system and the ability to connect USB devices. It has been confirmed as exploitable through USB device manipulation, though no public exploits have been observed in the wild (NVD).

Mitigation and workarounds

The issue has been fixed through two main commits: a6ecfb39ba9d7316057c ("usb: hso: fix error handling code of hso_create_net_device") and dcb713d53e2eadf42b878c12a471e74dc6ed3145 ("usb: hso: remove the bailout parameter"). These patches refactor the error handling code of hso_create_net_device and remove the unnecessary bailout parameter (Kernel Commit, SUSE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management