4.9
CVE-2021-3635
- EPSS 0.24%
- Veröffentlicht 13.08.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:02
- Erkennungen
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 5.5
Linux ≫ Linux Kernel Version 5.5 Update rc1
Linux ≫ Linux Kernel Version 5.5 Update rc2
Linux ≫ Linux Kernel Version 5.5 Update rc3
Linux ≫ Linux Kernel Version 5.5 Update rc4
Linux ≫ Linux Kernel Version 5.5 Update rc5
Linux ≫ Linux Kernel Version 5.5 Update rc6
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Fedoraproject ≫ Fedora Version 34
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.151 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
https://bugzilla.redhat.com/show_bug.cgi?id=1976946