6.7
CVSSv3

CVE-2021-20292

Published: 28/05/2021 Updated: 28/07/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

There is a flaw reported in the Linux kernel in versions prior to 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverage this vulnerability to escalate privileges and execute code in the context of the kernel.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

fedoraproject fedora 33

redhat enterprise linux 7.0

redhat enterprise linux 6.0

debian debian linux 9.0

Vendor Advisories

Several security issues were fixed in the Linux kernel ...
A security issue was found in the Linux kernel The specific flaw exists within DRM memory management The issue results from the lack of validating the existence of an object prior to performing operations on the object An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the kernel ...