VDB

HOTFIX-SA-2021%3A0012

HOTFIX-SA-2021%3A0012 PUBLISHED CVSS 7.800000190734863 HIGH

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. The compat IPT_SO_SET_REPLACE/IP6T_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel allows local users to gain privileges or cause a denial of service (heap memory corruption) via user namespace. This vulnerability is very similar to CVE-2016-3134 (CVSSv3 8.4 High) and CVE-2016-4997 (CVSSv3 7.8 High).

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alibaba Cloudkernel-hotfix-5928799-24.al7

Timeline

  • Jul 21, 2021 CVE Published
  • Jul 21, 2021 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›