2.1
CVSSv2

CVE-2021-20269

Published: 10/03/2022 Updated: 12/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions before 2.0.21-8 and RHEL versions before 2.0.20-47.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kexec-tools_project kexec-tools

Vendor Advisories

Debian Bug report logs - #985105 kexec-tools: CVE-2021-20269 Package: src:kexec-tools; Maintainer for src:kexec-tools is Khalid Aziz <khalid@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 12 Mar 2021 20:45:01 UTC Severity: important Tags: security, upstream Found in version kexec-tools ...
No description is available for this CVE ...
A security issue was found in the Linux kernel When there is a crash on the system, kdump generates the dmesg file with incorrect permissions ...