CVE-2021-20265: Medium severity linux kernel vulnerability
A flaw was found in the way memory resources were freed in the unixstreamrecvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
Other sources
A flaw was found in the way memory resources were freed in unixstreamrecvmsg function in the Linux kernel when signal was pending. An unprivileged local user could use this flaw to crash the system by exhausting available memory.
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fa0dc04df259ba2df3ce1920e9690c7842f8fa4b
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-20265?
CVE-2021-20265 has a high severity rating as it allows an unprivileged local user to crash the system by exhausting memory resources.
How do I fix CVE-2021-20265?
To fix CVE-2021-20265, update your Linux kernel to a version that is patched, such as 0:2.6.32-754.39.1.el6 or 0:3.10.0-1160.21.1.el7.
Who is affected by CVE-2021-20265?
CVE-2021-20265 affects users running specific versions of the Linux kernel and certain distributions such as Red Hat and Oracle.
Can CVE-2021-20265 be exploited remotely?
CVE-2021-20265 cannot be exploited remotely as it requires local access to the system.
What systems are vulnerable to CVE-2021-20265?
Vulnerable systems include those running specific versions of the Linux kernel and its derivatives, particularly those mentioned in the vulnerability details.