CVE-2021-3655
נמוכה 3.3
תיאור (מקור, אנגלית)
A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
מדדים
- CVSS 3.1
-
3.3 (LOW)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - CWE
- CWE-909, CWE-20
מוצרים מושפעים
linux: linux kernel; redhat: enterprise linux; debian: debian linux
קישורים
- https://bugzilla.redhat.com/show_bug.cgi?id=1984024 Issue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1984024 Issue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html Mailing ListThird Party Advisory