VDB

CVE-2021-38209

CVE-2021-38209 PUBLISHED CVSS 3.299999952316284 LOW

net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, and NF_SYSCTL_CT_BUCKETS sysctls.

EPSS 0.05% · 15.1th percentile

Risk Scores

CVSS v3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.05%
15.1th percentile

Affected Products

VendorProductVersions
n/an/a*
linuxlinux_kernel0

Timeline

  • Aug 8, 2021 CVE Published
  • Aug 9, 2021 EPSS Score
  • Oct 7, 2021 EPSS Score
  • Dec 4, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 1, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 29, 2022 EPSS Score
  • Jul 28, 2022 EPSS Score
  • Sep 25, 2022 EPSS Score
  • Nov 23, 2022 EPSS Score
  • Jan 20, 2023 EPSS Score

References

…and 6 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›