VDB
BDU%3A2021-04835
BDU%3A2021-04835
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость компонента drivers/gpu/drm/nouveau/nouveau_sgdma.c ядра операционной системы Linux , связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код с root привилегиями
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, Canonical Ltd., ООО «РусБИТех-Астра» | Red Hat Enterprise Linux, Debian GNU/Linux, Ubuntu, Astra Linux Special Edition (запись в едином реестре российских программ №369), Linux |
Timeline
- Oct 5, 2021 CVE Published
- Jun 3, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1939686 url
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20292 url
- https://git.kernel.org/linus/5de5b6ecf97a021f29403aa272cb4e03318ef586 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.59 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.16 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.2 url
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html url
- https://security-tracker.debian.org/tracker/CVE-2021-20292 url
- https://ubuntu.com/security/notices/USN-4946-1 url
- https://ubuntu.com/security/notices/USN-5343-1 url
- https://usn.ubuntu.com/usn/usn-4946-1 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20210730SE16 url
- https://www.cve.org/CVERecord?id=CVE-2021-20292 url
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.263 advisory
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.140 advisory
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.298 advisory
- https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-20292.xml advisory
- https://ubuntu.com/security/CVE-2021-20292 advisory