CVE-2021-29265: Race Condition
An issue was discovered in the Linux kernel before 5.11.7. usbipsockfdstore in drivers/usb/usbip/stubdev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and shared status, aka CID-9380afd6df70.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.259-1Fixed in 6.1.176-1Fixed in 6.1.177-1Fixed in 6.12.94-1Fixed in 6.12.95-1Fixed in 7.1.3-1Fixed in 7.1.4-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.11.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CID-9380afd6df70
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29265?
CVE-2021-29265 has a severity rating associated with a denial of service vulnerability in the Linux kernel.
How do I fix CVE-2021-29265?
To fix CVE-2021-29265, you should upgrade to Linux kernel version 5.11.7 or later, or apply the recommended patches.
Which Linux versions are affected by CVE-2021-29265?
CVE-2021-29265 affects Linux kernel versions prior to 5.11.7.
Is CVE-2021-29265 exploitable remotely?
CVE-2021-29265 is a local denial of service vulnerability and typically requires local access to exploit.
What impact does CVE-2021-29265 have on system stability?
Exploiting CVE-2021-29265 can lead to a general protection fault, potentially causing system instability.