Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20317

Опубликовано: 23 сент. 2021
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP.

A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP. The highest threat from this vulnerability is system availability.

Меры по смягчению последствий

In order to mitigate this issue, it is possible to prevent the affected code by loading the kvm module with "pi_inject_timer=0" parameter.

rmmod kvm_intel kvm modprobe kvm pi_inject_timer=0 modprobe kvm_intel

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelWill not fix
Red Hat Enterprise Linux 7kernel-rtWill not fix
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2021:464615.11.2021
Red Hat Enterprise Linux 8kernelFixedRHSA-2021:464715.11.2021
Red Hat Enterprise Linux 8.2 Extended Update Supportkernel-rtFixedRHSA-2021:487530.11.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportkernelFixedRHSA-2021:487130.11.2021
Red Hat Enterprise Linux 8.4 Extended Update Supportkernel-rtFixedRHSA-2021:464815.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=2005258kernel: timer tree corruption leads to missing wakeup and system freeze

EPSS

Процентиль: 1%
0.00012
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 3 лет назад

A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP.

CVSS3: 4.4
nvd
больше 3 лет назад

A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP.

CVSS3: 4.4
debian
больше 3 лет назад

A flaw was found in the Linux kernel. A corrupted timer tree caused th ...

CVSS3: 4.4
github
около 3 лет назад

A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP.

CVSS3: 4.4
fstec
почти 6 лет назад

Уязвимость функции timerqueue_add компонента lib/timerqueue.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 1%
0.00012
Низкий

4.4 Medium

CVSS3

Уязвимость CVE-2021-20317