PT-2021-4242 · Linux+5 · Linux Kernel+5

Tatsuhiko Yasumatsu

·

Published

2021-08-06

·

Updated

2024-06-15

·

CVE-2021-38166

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.13.8
Description The issue is related to an integer overflow and out-of-bounds write in the kernel/bpf/hashtab.c component of the Linux kernel. This occurs when many elements are placed in a single bucket. Exploitation of this issue may allow an attacker to impact the integrity, availability, and confidentiality of data. It is noted that exploitation might be impractical without the CAP SYS ADMIN capability.
Recommendations For Linux kernel versions through 5.13.8, update to a version later than 5.13.8 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific issue.

Exploit

Fix

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2486
ALT-PU-2021-2564
ALT-PU-2021-2616
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-6581
BDU:2021-04849
CVE-2021-38166
DSA-4978-1
MGASA-2021-0409
MGASA-2021-0410
OPENSUSE-SU-2021:3179-1
OPENSUSE-SU-2021:3205-1
OPENSUSE-SU-2021_3179-1
OPENSUSE-SU-2021_3205-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
SUSE-SU-2021:3179-1
SUSE-SU-2021:3205-1
SUSE-SU-2021:3205-2
USN-5096-1
USN-5113-1
USN-5115-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu