vulnerability
Oracle Linux: CVE-2021-33909: ELSA-2021-9374: kernel security update (IMPORTANT) (Multiple Advisories)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:L/AC:L/Au:S/C:C/I:C/A:C) | 2021-07-20 | 2021-07-22 | 2025-01-23 |
Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
2021-07-20
Added
2021-07-22
Modified
2025-01-23
Description
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
An out-of-bounds write flaw was found in the Linux kernel's seq_file in the Filesystem layer. This flaw allows a local attacker with a user privilege to gain access to out-of-bound memory, leading to a system crash, leak of internal kernel information and can escalate privileges. The issue results from not validating the size_t-to-int conversion prior to performing operations. The highest threat from this vulnerability is to data integrity, confidentiality and system availability.
An out-of-bounds write flaw was found in the Linux kernel's seq_file in the Filesystem layer. This flaw allows a local attacker with a user privilege to gain access to out-of-bound memory, leading to a system crash, leak of internal kernel information and can escalate privileges. The issue results from not validating the size_t-to-int conversion prior to performing operations. The highest threat from this vulnerability is to data integrity, confidentiality and system availability.
Solution(s)
oracle-linux-upgrade-kerneloracle-linux-upgrade-kernel-uek
References
- CVE-2021-33909
- https://attackerkb.com/topics/CVE-2021-33909
- ELSA-ELSA-2021-9374
- ELSA-ELSA-2021-9406
- ELSA-ELSA-2021-9410
- ELSA-ELSA-2021-2714
- ELSA-ELSA-2021-9372
- ELSA-ELSA-2021-9369
- ELSA-ELSA-2021-2725
- ELSA-ELSA-2021-9368
- ELSA-ELSA-2021-9404
- ELSA-ELSA-2021-9395
- ELSA-ELSA-2021-9371
- ELSA-ELSA-2021-9407
- ELSA-ELSA-2021-9370

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.