CVE-2021-3501
גבוהה 7.1
תיאור (מקור, אנגלית)
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
מדדים
- CVSS 3.1
-
7.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-10/8/2026
- CWE
- CWE-787
מוצרים מושפעים
linux: linux kernel; redhat: enterprise linux; redhat: enterprise linux for real time; redhat: enterprise linux for real time for nfv; redhat: enterprise linux for real time for nfv tus; redhat: enterprise linux for real time tus; fedoraproject: fedora; redhat: virtualization; redhat: virtualization host; netapp: cloud backup; netapp: solidfire baseboard management controller firmware; netapp: h300s firmware; netapp: h300s; netapp: h500s firmware; netapp: h500s
קישורים
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Mailing ListPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Mailing ListPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1950136 Issue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1950136 Issue TrackingPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210618-0008/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210618-0008/ Third Party Advisory