Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3347

Опубликовано: 28 янв. 2021
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

A flaw was found in the Linux kernel. A use-after-free memory flaw in the Fast Userspace Mutexes functionality allowing a local user to crash the system or escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 6 Extended Lifecycle SupportkernelFixedRHSA-2021:273520.07.2021
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2021:231608.06.2021
Red Hat Enterprise Linux 7kernel-altFixedRHSA-2021:137927.04.2021
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2021:228508.06.2021
Red Hat Enterprise Linux 7kernelFixedRHSA-2021:231408.06.2021
Red Hat Enterprise Linux 7.2 Advanced Update SupportkernelFixedRHSA-2021:339931.08.2021
Red Hat Enterprise Linux 7.3 Advanced Update SupportkernelFixedRHSA-2021:273320.07.2021
Red Hat Enterprise Linux 7.4 Advanced Update SupportkernelFixedRHSA-2021:273220.07.2021
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportkernelFixedRHSA-2021:273220.07.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1922249kernel: Use after free via PI futex state

EPSS

Процентиль: 50%
0.00269
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

CVSS3: 7.8
nvd
больше 4 лет назад

An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

CVSS3: 7.8
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 4 лет назад

An issue was discovered in the Linux kernel through 5.10.11. PI futexe ...

github
около 3 лет назад

An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

EPSS

Процентиль: 50%
0.00269
Низкий

7 High

CVSS3