7.8

CVE-2021-3600

It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.14.115 < 4.14.308
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.206
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.98
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.16
Linux ≫ Linux Kernel Version 5.11 Update rc1
Linux ≫ Linux Kernel Version 5.11 Update rc2
Linux ≫ Linux Kernel Version 5.11 Update rc3
Linux ≫ Linux Kernel Version 5.11 Update rc4
Linux ≫ Linux Kernel Version 5.11 Update rc5
Linux ≫ Linux Kernel Version 5.11 Update rc6
Linux ≫ Linux Kernel Version 5.11 Update rc7
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition esm
Fedoraproject ≫ Fedora Version 34
Redhat ≫ Enterprise Linux Version 8.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.197
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Canonical 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3600
Product
https://git.kernel.org/linus/e88b2c6e5a4d9ce30d75391e4d950da74bb2bd90
Patch
Vendor Advisory
Mailing List
https://ubuntu.com/security/notices/USN-5003-1
Third Party Advisory