7.8
CVSSv3

CVE-2021-41864

Published: 02/10/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel prior to 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

netapp cloud backup -

netapp solidfire -

netapp hci management node -

netapp h410c_firmware -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h300e_firmware -

netapp h500e_firmware -

netapp h700e_firmware -

netapp h410s_firmware -

netapp solidfire_baseboard_management_controller_firmware -

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks CVE-2020-29374 Jann Horn of Google reported a flaw in Linux's virtual memory management A parent and child process initially share all their memory, but when either writes to a shared page, ...
Synopsis Important: Red Hat Advanced Cluster Management 25 security updates, images, and bug fixes Type/Severity Security Advisory: Important Topic Red Hat Advanced Cluster Management for Kubernetes 250 is now generally availableRed Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability ...
Synopsis Moderate: Migration Toolkit for Containers (MTC) 165 security and bug fix update Type/Severity Security Advisory: Moderate Topic The Migration Toolkit for Containers (MTC) 165 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated ...
概述 Moderate: Red Hat Advanced Cluster Management 2311 security updates and bug fixes 类型/严重性 Security Advisory: Moderate 标题 Red Hat Advanced Cluster Management for Kubernetes 2311 generalavailability release images, which provide security updates and bug fixesRed Hat Product Security has rated this update as having a sec ...
Synopsis Moderate: Red Hat Advanced Cluster Management 245 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 245 GeneralAvailability release images, which fix bugs and update container imagesRed Hat Product Security has rated this update as having a security ...
Synopsis Moderate: Migration Toolkit for Containers (MTC) 172 security and bug fix update Type/Severity Security Advisory: Moderate Topic The Migration Toolkit for Containers (MTC) 172 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
prealloc_elems_and_freelist in kernel/bpf/stackmapc in the Linux kernel through 5149 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write ...
prealloc_elems_and_freelist in kernel/bpf/stackmapc in the Linux kernel through 5149 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write ...
A flaw was found in the Linux kernel A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueuec This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP The highest threat from this vulnerability is ...
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS A local user could use this flaw to crash the system (CVE-2021-20321) A flaw was found in the Linux kernel A memory leak in the ccp-ops crypto driver can allow attackers to cause a denial of service ...
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS A local user could use this flaw to crash the system (CVE-2021-20321) A flaw was found in the Linux kernel A memory leak in the ccp-ops crypto driver can allow attackers to cause a denial of service ...
A flaw was found in the Linux kernel A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueuec This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP The highest threat from this vulnerability is ...
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS A local user could use this flaw to crash the system (CVE-2021-20321) A flaw was found in the Linux kernel A memory leak in the ccp-ops crypto driver can allow attackers to cause a denial of service ...
A flaw was found in the Linux kernel A memory leak in the ccp-ops crypto driver can allow attackers to cause a denial of service This vulnerability is similar with the older CVE-2019-18808 The highest threat from this vulnerability is to system availability (CVE-2021-3744) A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() ...
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS A local user could use this flaw to crash the system (CVE-2021-20321) A flaw was found in the Linux kernel A memory leak in the ccp-ops crypto driver can allow attackers to cause a denial of service ...