Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Andra Paraschiv

Researcher fromAmazon
#45660of 53,635
5.5Total CVSS
Vulnerabilities · 1
PT-2021-8075
5.5
2021-12-21
Linux · Linux Kernel · CVE-2021-46927
**Name of the Vulnerable Software and Affected Versions** Linux kernel (affected versions not specified) **Description** The vulnerability is related to the use of the `get user pages unlocked()` call to handle mmap assert in the `nitro enclaves` component of the Linux kernel. After a specific commit, the call to `get user pages()` triggers the mmap assert, which can lead to a denial of service. The issue is caused by the lack of proper locking, as indicated by the `mmap assert locked()` function. The vulnerability can be exploited by an attacker to cause a denial of service. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.