VDB

HOTFIX-SA-2021%3A0018

HOTFIX-SA-2021%3A0018 PUBLISHED CVSS 7.800000190734863 HIGH

An out-of-bounds write flaw was found in the Linux kernel's seq_file in the Filesystem layer. This flaw allows a local attacker with a user privilege to gain access to out-of-bound memory, leading to a system crash or a leak of internal kernel information. The issue results from not validating the size_t-to-int conversion prior to performing operations. This vulnerability is a type conversion vulnerability in the filesystem layer of the Linux kernel. A type conversion vulnerability is a condition when converting between two types and can lead to an overflow, creating a large negative value.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alibaba Cloudkernel-hotfix-5956925-21.al7

Timeline

  • Jul 23, 2021 CVE Published
  • Jul 23, 2021 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›