VDB
HOTFIX-SA-2021%3A0018
HOTFIX-SA-2021%3A0018
PUBLISHED
CVSS 7.800000190734863 HIGH
An out-of-bounds write flaw was found in the Linux kernel's seq_file in the Filesystem layer. This flaw allows a local attacker with a user privilege to gain access to out-of-bound memory, leading to a system crash or a leak of internal kernel information. The issue results from not validating the size_t-to-int conversion prior to performing operations. This vulnerability is a type conversion vulnerability in the filesystem layer of the Linux kernel. A type conversion vulnerability is a condition when converting between two types and can lead to an overflow, creating a large negative value.
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | kernel-hotfix-5956925-21.al7 |
Timeline
- Jul 23, 2021 CVE Published
- Jul 23, 2021 CVE Updated