Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-26392

Опубликовано: 08 нояб. 2022
Источник: redhat
CVSS3: 6.4

Описание

Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.

A flaw was found in hw. Insufficient verification of missing size checks in the 'LoadModule' may lead to an out-of-bounds write, potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious Trusted Application (TA).

Меры по смягчению последствий

Please contact AMD for more updates on this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2133522hw: amd: Insufficient verification in 'LoadModule' may lead to an out-of-bounds write

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
около 3 лет назад

Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.

CVSS3: 7.8
github
около 3 лет назад

Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.

6.4 Medium

CVSS3