Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-344470
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 07:56
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T07:56:19.273492+00:00",
"id": "EUVD-2026-344470"
}
CVE-2021-47388 (GCVE-0-2021-47388)
Vulnerability from cvelistv5 – Published: 2024-05-21 15:03 – Updated: 2026-08-05 08:47
VLAI
EPSS
VEX
Title
mac80211: fix use-after-free in CCMP/GCMP RX
Summary
In the Linux kernel, the following vulnerability has been resolved:
mac80211: fix use-after-free in CCMP/GCMP RX
When PN checking is done in mac80211, for fragmentation we need
to copy the PN to the RX struct so we can later use it to do a
comparison, since commit bf30ca922a0c ("mac80211: check defrag
PN against current frame").
Unfortunately, in that commit I used the 'hdr' variable without
it being necessarily valid, so use-after-free could occur if it
was necessary to reallocate (parts of) the frame.
Fix this by reloading the variable after the code that results
in the reallocations, if any.
This fixes https://bugzilla.kernel.org/show_bug.cgi?id=214401.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-09-10 15:38 UTC
Assigner
References
8 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
608b0a2ae928a74a2f89e02227339dd79cdb63cf , < 447d001b875d0e7f211c4ba004916028da994258
(git)
Affected: d0f613fe6de344dc17ba04a88921a2094c13d3fa , < 31de381aef0ab1b342f62485118dc8a19363dc78 (git) Affected: a9b57952fed41556c950a92123086724eaf11919 , < f556e1d6fb9f2923a9a36f3df638c7d79ba09dbb (git) Affected: 0f716b48ed25503e6961f4b5b40ece36f7e4ed26 , < 3d5d629c99c468458022e9b381789de3595bf4dd (git) Affected: c8b3a6150dc8ac78d5fdd5fbdfc4806249ef8b2c , < 50149e0866a82cef33e680ee68dc380a5bc75d32 (git) Affected: e64ea0597050157f926ac2ba9b478a44ee5be945 , < 57de2dcb18742dc2860861c9f496da7d42b67da0 (git) Affected: bf30ca922a0c0176007e074b0acc77ed345e9990 , < 27d3eb5616ee2c0a3b30c3fa34813368ed1f3dc9 (git) Affected: bf30ca922a0c0176007e074b0acc77ed345e9990 , < 94513069eb549737bcfc3d988d6ed4da948a2de8 (git) Affected: 1f0bf30c01d3f4de7d6c5e27b102a808c5646676 (git) Affected: 4.4.271 , < 4.4.286 (semver) Affected: 4.9.271 , < 4.9.285 (semver) Affected: 4.14.235 , < 4.14.249 (semver) Affected: 4.19.193 , < 4.19.209 (semver) Affected: 5.4.124 , < 5.4.151 (semver) Affected: 5.10.42 , < 5.10.71 (semver) Affected: 5.12.9 , < 5.13 (semver) |
|
| Linux | Linux |
Affected:
5.13
Unaffected: 0 , < 5.13 (semver) Unaffected: 4.4.286 , ≤ 4.4.* (semver) Unaffected: 4.9.285 , ≤ 4.9.* (semver) Unaffected: 4.14.249 , ≤ 4.14.* (semver) Unaffected: 4.19.209 , ≤ 4.19.* (semver) Unaffected: 5.4.151 , ≤ 5.4.* (semver) Unaffected: 5.10.71 , ≤ 5.10.* (semver) Unaffected: 5.14.10 , ≤ 5.14.* (semver) Unaffected: 5.15 , ≤ * (original_commit_for_fix) |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T05:39:58.947Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/447d001b875d0e7f211c4ba004916028da994258"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/31de381aef0ab1b342f62485118dc8a19363dc78"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/f556e1d6fb9f2923a9a36f3df638c7d79ba09dbb"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/3d5d629c99c468458022e9b381789de3595bf4dd"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/50149e0866a82cef33e680ee68dc380a5bc75d32"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/57de2dcb18742dc2860861c9f496da7d42b67da0"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/27d3eb5616ee2c0a3b30c3fa34813368ed1f3dc9"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/94513069eb549737bcfc3d988d6ed4da948a2de8"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2021-47388",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-10T15:38:19.729589Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-11T17:33:43.903Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mac80211/wpa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "447d001b875d0e7f211c4ba004916028da994258",
"status": "affected",
"version": "608b0a2ae928a74a2f89e02227339dd79cdb63cf",
"versionType": "git"
},
{
"lessThan": "31de381aef0ab1b342f62485118dc8a19363dc78",
"status": "affected",
"version": "d0f613fe6de344dc17ba04a88921a2094c13d3fa",
"versionType": "git"
},
{
"lessThan": "f556e1d6fb9f2923a9a36f3df638c7d79ba09dbb",
"status": "affected",
"version": "a9b57952fed41556c950a92123086724eaf11919",
"versionType": "git"
},
{
"lessThan": "3d5d629c99c468458022e9b381789de3595bf4dd",
"status": "affected",
"version": "0f716b48ed25503e6961f4b5b40ece36f7e4ed26",
"versionType": "git"
},
{
"lessThan": "50149e0866a82cef33e680ee68dc380a5bc75d32",
"status": "affected",
"version": "c8b3a6150dc8ac78d5fdd5fbdfc4806249ef8b2c",
"versionType": "git"
},
{
"lessThan": "57de2dcb18742dc2860861c9f496da7d42b67da0",
"status": "affected",
"version": "e64ea0597050157f926ac2ba9b478a44ee5be945",
"versionType": "git"
},
{
"lessThan": "27d3eb5616ee2c0a3b30c3fa34813368ed1f3dc9",
"status": "affected",
"version": "bf30ca922a0c0176007e074b0acc77ed345e9990",
"versionType": "git"
},
{
"lessThan": "94513069eb549737bcfc3d988d6ed4da948a2de8",
"status": "affected",
"version": "bf30ca922a0c0176007e074b0acc77ed345e9990",
"versionType": "git"
},
{
"status": "affected",
"version": "1f0bf30c01d3f4de7d6c5e27b102a808c5646676",
"versionType": "git"
},
{
"lessThan": "4.4.286",
"status": "affected",
"version": "4.4.271",
"versionType": "semver"
},
{
"lessThan": "4.9.285",
"status": "affected",
"version": "4.9.271",
"versionType": "semver"
},
{
"lessThan": "4.14.249",
"status": "affected",
"version": "4.14.235",
"versionType": "semver"
},
{
"lessThan": "4.19.209",
"status": "affected",
"version": "4.19.193",
"versionType": "semver"
},
{
"lessThan": "5.4.151",
"status": "affected",
"version": "5.4.124",
"versionType": "semver"
},
{
"lessThan": "5.10.71",
"status": "affected",
"version": "5.10.42",
"versionType": "semver"
},
{
"lessThan": "5.13",
"status": "affected",
"version": "5.12.9",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mac80211/wpa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.*",
"status": "unaffected",
"version": "4.4.286",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.9.*",
"status": "unaffected",
"version": "4.9.285",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.14.*",
"status": "unaffected",
"version": "4.14.249",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.19.*",
"status": "unaffected",
"version": "4.19.209",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.151",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.71",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.14.*",
"status": "unaffected",
"version": "5.14.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "5.15",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.4.286",
"versionStartIncluding": "4.4.271",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.9.285",
"versionStartIncluding": "4.9.271",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.14.249",
"versionStartIncluding": "4.14.235",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.19.209",
"versionStartIncluding": "4.19.193",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.151",
"versionStartIncluding": "5.4.124",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.71",
"versionStartIncluding": "5.10.42",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.14.10",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.12.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: fix use-after-free in CCMP/GCMP RX\n\nWhen PN checking is done in mac80211, for fragmentation we need\nto copy the PN to the RX struct so we can later use it to do a\ncomparison, since commit bf30ca922a0c (\"mac80211: check defrag\nPN against current frame\").\n\nUnfortunately, in that commit I used the \u0027hdr\u0027 variable without\nit being necessarily valid, so use-after-free could occur if it\nwas necessary to reallocate (parts of) the frame.\n\nFix this by reloading the variable after the code that results\nin the reallocations, if any.\n\nThis fixes https://bugzilla.kernel.org/show_bug.cgi?id=214401."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable code runs in mac80211\u2019s over-the-air RX decrypt path (ieee80211_rx \u2192 ieee80211_rx_h_decrypt \u2192 ieee80211_crypto_ccmp/gcmp_decrypt) when processing CCMP/GCMP Wi\u2011Fi frames on the same RF/LAN segment, matching WiFi frame-injection Adjacent scoring\u2014not a local syscall-only path.\nAC:L - An adjacent peer that can send validly encrypted CCMP/GCMP frames (e.g., SoftAP client or associated station) can drive this decrypt path; the UAF was observed in normal RX on iwl3945/KFENCE, and UAF trigger conditions here are not an attacker-uncontrollable race.\nPR:N - Exploitation needs no account or capabilities on the victim host\u2014only the ability to deliver encrypted 802.11 frames that mac80211 decrypts (reasonable SoftAP/hotspot or peer scenarios), so privileges required are None.\nUI:N - Encrypted frame RX and decrypt run automatically in the mac80211 RX softirq/NAPI path whenever the interface is operating; no extra victim action is required at exploit time.\nS:U - Impact stays inside the host kernel wireless stack under the same OS security authority; this is not a VM escape, IOMMU bypass, or other cross-boundary breakout.\nC:H - This is a use-after-free of skb header memory (ieee80211_is_frag(hdr) reads freed data); per scoring guidance a UAF enables control of freed-object contents and arbitrary-read primitives.\nI:H - Use-after-free of the reallocated frame buffer enables heap reuse/spray and escalation to write/control-flow hijack under standard kernel UAF exploitation models.\nA:H - The UAF read was detected as a KFENCE use-after-free and can oops/panic the kernel (or crash under KASAN/KFENCE), fully denying availability."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T08:47:34.556Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/447d001b875d0e7f211c4ba004916028da994258"
},
{
"url": "https://git.kernel.org/stable/c/31de381aef0ab1b342f62485118dc8a19363dc78"
},
{
"url": "https://git.kernel.org/stable/c/f556e1d6fb9f2923a9a36f3df638c7d79ba09dbb"
},
{
"url": "https://git.kernel.org/stable/c/3d5d629c99c468458022e9b381789de3595bf4dd"
},
{
"url": "https://git.kernel.org/stable/c/50149e0866a82cef33e680ee68dc380a5bc75d32"
},
{
"url": "https://git.kernel.org/stable/c/57de2dcb18742dc2860861c9f496da7d42b67da0"
},
{
"url": "https://git.kernel.org/stable/c/27d3eb5616ee2c0a3b30c3fa34813368ed1f3dc9"
},
{
"url": "https://git.kernel.org/stable/c/94513069eb549737bcfc3d988d6ed4da948a2de8"
}
],
"title": "mac80211: fix use-after-free in CCMP/GCMP RX",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2021-47388",
"datePublished": "2024-05-21T15:03:47.574Z",
"dateReserved": "2024-05-21T14:58:30.813Z",
"dateUpdated": "2026-08-05T08:47:34.556Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…