ZeroHour

CVE-2021-3609

PoC
CVSS 3.1
7.0 high
EPSS
<1%p37
Published
()
Modified
Description

.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.

Vendors
linuxredhatnetapp
Products
linux kernel, 3scale api management, build of quarkus, codeready linux builder eus, codeready linux builder for power little endian eus, openshift container platform, virtualization, virtualization host, enterprise linux aus, enterprise linux eus, enterprise linux for ibm z systems eus, enterprise linux for ibm z systems eus s390x
Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.