ZeroHour

CVE-2021-3501

CVSS 3.1
7.1 high
EPSS
<1%p31
Published
()
Modified
Description

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.

Vendors
linuxredhatfedoraprojectnetapp
Products
linux kernel, enterprise linux, enterprise linux for real time, enterprise linux for real time for nfv, enterprise linux for real time for nfv tus, enterprise linux for real time tus, fedora, virtualization, virtualization host, cloud backup, solidfire baseboard management controller firmware, h300s firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.