Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3543

Опубликовано: 29 апр. 2021
Источник: redhat
CVSS3: 6.7

Описание

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

Отчет

This flaw is rated as having a Moderate impact because in the default configuration, the issue can only be triggered by a privileged local user (with access to the ne group if this user manages Enclaves VMs).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2021:216901.06.2021
Red Hat Enterprise Linux 8kernelFixedRHSA-2021:216801.06.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1953022kernel: nitro_enclaves stale file descriptors on failed usercopy

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 4 лет назад

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

CVSS3: 6.7
nvd
около 4 лет назад

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

CVSS3: 6.7
debian
около 4 лет назад

A flaw null pointer dereference in the Nitro Enclaves kernel driver wa ...

CVSS3: 6.7
github
около 3 лет назад

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

CVSS3: 6.7
fstec
около 4 лет назад

Уязвимость драйвера Nitro Enclaves ядра операционной системы Linux, связанная с ошибками разыменования указателя, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

6.7 Medium

CVSS3