7.1
CVSSv3

CVE-2021-3501

Published: 06/05/2021 Updated: 13/05/2022
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

A flaw was found in the Linux kernel in versions prior to 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

redhat enterprise linux 8.0

redhat enterprise linux for real time 8

redhat enterprise linux for real time for nfv tus 8.4

redhat enterprise linux for real time tus 8.4

redhat enterprise linux for real time for nfv 8

fedoraproject fedora 33

redhat virtualization_host 4.0

redhat virtualization 4.0

netapp cloud backup -

netapp solidfire baseboard management controller firmware -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h300e_firmware -

netapp h500e_firmware -

netapp h700e_firmware -

netapp h410s_firmware -

netapp h410c_firmware -

Vendor Advisories

A flaw was found in the Linux kernel The value of internalndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write The highest threat from this vulnerability is to data integrity and system availability ...
A use-after-free flaw was found in the Linux kernel's NFC LLCP protocol implementation in the way the user performs manipulation with an unknown input for the llcp_sock_bind() function This flaw allows a local user to crash or escalate their privileges on the system (CVE-2020-25670) A use-after-free flaw was found in the Linux kernel's NFC LLCP p ...
A security issue was found in the Linux kernel before version 51116 The value of internalndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write ...