CVE-2021-38166
גבוהה 7.8
תיאור (מקור, אנגלית)
In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-10/8/2026
- CWE
- CWE-190, CWE-787
מוצרים מושפעים
linux: linux kernel; fedoraproject: fedora; debian: debian linux
קישורים
- https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=c4eb1f4… PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=c4eb1f4… PatchVendor Advisory
- https://lore.kernel.org/bpf/20210806150419.109658-1-th.yasumatsu%40gmail.com/ Patch
- https://lore.kernel.org/bpf/20210806150419.109658-1-th.yasumatsu%40gmail.com/ Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210909-0001/ Third Party Advisory
- https://www.debian.org/security/2021/dsa-4978 Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Third Party Advisory