8
CVE-2021-4157
- EPSS 0.05%
- Veröffentlicht 25.03.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:01
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.0 < 4.4.269
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.269
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.233
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.191
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.120
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.38
Linux ≫ Linux Kernel Version >= 5.11 < 5.11.22
Linux ≫ Linux Kernel Version >= 5.12 < 5.12.5
Fedoraproject ≫ Fedora Version35
Netapp ≫ H300e Firmware Version-
Netapp ≫ H300s Firmware Version-
Netapp ≫ H500e Firmware Version-
Netapp ≫ H500s Firmware Version-
Netapp ≫ H700e Firmware Version-
Netapp ≫ H700s Firmware Version-
Netapp ≫ H410s Firmware Version-
Oracle ≫ Communications Cloud Native Core Binding Support Function Version22.1.1
Oracle ≫ Communications Cloud Native Core Binding Support Function Version22.1.3
Oracle ≫ Communications Cloud Native Core Binding Support Function Version22.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.151 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.4 | 4.4 | 10 |
AV:A/AC:M/Au:S/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.