CVE-2021-47670
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Apr 17, 2025
Updated: Apr 21, 2025
CWE ID 416
Summary
CVE-2021-47670 is a vulnerability affecting the Linux kernel that has been addressed. This issue lies in the 'can: peak_usb' module, specifically in the 'peak_usb_netif_rx_ni' function. After calling this function, SkB memory is dereferenced unsafely, leading to a use-after-free condition. Consequently, the can_frame cf, which aliases the SkB memory, is accessed in an unsafe manner following the 'peak_usb_netif_rx_ni' call. The vulnerability is mitigated by reordering the lines in the code.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.