First published: Thu Sep 02 2021(Updated: )
A vulnerability was found in Linux Kernel, where a type confusion problem in check_map_func_compatibility() may lead to free arbitrary kernel memory. Reference: <a href="https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=5b029a32cfe4600f5e10e36b41778506b90fd4de">https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=5b029a32cfe4600f5e10e36b41778506b90fd4de</a> <a href="https://www.zerodayinitiative.com/advisories/ZDI-21-1148/">https://www.zerodayinitiative.com/advisories/ZDI-21-1148/</a>
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | ||
redhat/Kernel | <5.14 | 5.14 |
Linux Linux kernel | >=5.8<5.10.62 | |
Linux Linux kernel | >=5.11<5.13.14 | |
Netapp H410c Firmware | ||
Netapp H410c | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H300e Firmware | ||
Netapp H300e | ||
Netapp H500e Firmware | ||
Netapp H500e | ||
Netapp H700e Firmware | ||
Netapp H700e | ||
Netapp H410s Firmware | ||
Netapp H410s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34866 is a vulnerability in the Linux Kernel that allows local attackers to escalate privileges on affected installations.
CVE-2021-34866 has a severity value of 8.8, which is considered high.
CVE-2021-34866 affects Linux Kernel versions 5.8 to 5.10.62, and versions 5.11 to 5.13.14.
To exploit CVE-2021-34866, an attacker must first obtain the ability to execute low-privileged code on the target system.
You can find more information about CVE-2021-34866 at the following references: [ZDI-21-1148](https://www.zerodayinitiative.com/advisories/ZDI-21-1148/) and [Netapp Advisory](https://security.netapp.com/advisory/ntap-20220217-0008/).