Severity
High
Analysis Summary
CVE-2021-3483
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a use-after-free flaw in nosy driver in Linux/drivers/firewire/nosy.c. By sending a specially-crafted ioctl call with NOSY_IOC_START command, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
Impact
Unauthorized Access
Affected Vendors
Linux
Affected Products
Linux Kernel 5.11
Remediation
Refer to Linux Kernel GIT Repository for patch, upgrade or suggested workaround information.