PT-2021-4148 · Linux+8 · Linux Kernel+8

Haoran Luo

·

Published

2021-07-20

·

Updated

2023-08-14

·

CVE-2021-3679

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.14-rc3
Description A lack of CPU resource in the Linux kernel tracing module functionality was found in the way a user uses the trace ring buffer in a specific way. Only privileged local users, with CAP SYS ADMIN capability, could use this flaw to starve the resources, causing a denial of service.
Recommendations For versions prior to 5.14-rc3, update to version 5.14-rc3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the trace ring buffer functionality to minimize the risk of exploitation. Additionally, limiting the capabilities of local users to prevent them from obtaining the CAP SYS ADMIN capability can also help mitigate the risk.

Exploit

Fix

DoS

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4356
ALT-PU-2021-2824
ALT-PU-2021-2926
ALT-PU-2021-3041
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-6577
BDU:2021-04741
CESA-2021_4140
CESA-2021_4356
CVE-2021-3679
DLA-2785-1
DLA-2843-1
DSA-4978-1
OESA-2021-1318
OPENSUSE-SU-2021:1142-1
OPENSUSE-SU-2021:3179-1
OPENSUSE-SU-2021:3205-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_1142-1
OPENSUSE-SU-2021_3179-1
OPENSUSE-SU-2021_3205-1
OPENSUSE-SU-2021_3876-1
RHSA-2021:4140
RHSA-2021:4356
RHSA-2021_4140
RHSA-2021_4356
SUSE-SU-2021:14849-1
SUSE-SU-2021:3177-1
SUSE-SU-2021:3178-1
SUSE-SU-2021:3179-1
SUSE-SU-2021:3192-1
SUSE-SU-2021:3205-1
SUSE-SU-2021:3205-2
SUSE-SU-2021:3206-1
SUSE-SU-2021:3207-1
SUSE-SU-2021:3217-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3929-1
SUSE-SU-2021:3935-1
SUSE-SU-2021:3969-1
SUSE-SU-2021:3972-1
SUSE-SU-2021_14849-1
USN-5091-1
USN-5091-2
USN-5091-3
USN-5092-1
USN-5092-2
USN-5092-3
USN-5094-1
USN-5094-2
USN-5096-1
USN-5115-1
USN-5299-1
USN-5343-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu