ZeroHour

CVE-2021-38160

CVSS 3.1
7.8 high
EPSS
<1%p33
Published
()
Modified
Description

In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior

Vendors
linuxnetappdebianredhat
Products
linux kernel, hci bootstrap os, hci management node, solidfire, element software, debian linux, enterprise linux
Weakness
CWE-120
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.