First published: Tue Apr 13 2021(Updated: )
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-305.3.1.rt7.75.el8_4 | 0:4.18.0-305.3.1.rt7.75.el8_4 |
redhat/kernel | <0:4.18.0-305.3.1.el8_4 | 0:4.18.0-305.3.1.el8_4 |
redhat/redhat-virtualization-host | <0:4.4.6-20210615.0.el8_4 | 0:4.4.6-20210615.0.el8_4 |
redhat/kernel | <5.12 | 5.12 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
Linux Kernel | <5.12 | |
Red Hat Enterprise Linux | =8.0 | |
redhat enterprise Linux for real time | =8 | |
redhat enterprise Linux for real time for nfv | =8 | |
redhat enterprise Linux for real time for nfv tus | =8.4 | |
redhat enterprise Linux for real time tus | =8.4 | |
Fedora | =33 | |
All of | ||
Any of | ||
Red Hat Enterprise Virtualization | =4.0 | |
redhat virtualization host | =4.0 | |
Red Hat Enterprise Linux | =8.0 | |
netapp cloud backup | ||
netapp solidfire baseboard management controller firmware | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h300e firmware | ||
netapp h300e | ||
All of | ||
netapp h500e firmware | ||
netapp h500e | ||
All of | ||
netapp h700e firmware | ||
netapp h700e | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
Red Hat Enterprise Virtualization | =4.0 | |
redhat virtualization host | =4.0 | |
Red Hat Enterprise Linux | =8.0 | |
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h300e firmware | ||
netapp h300e | ||
netapp h500e firmware | ||
netapp h500e | ||
netapp h700e firmware | ||
netapp h700e | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h410c firmware | ||
netapp h410c |
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-3501 has a high severity rating due to its impact on data integrity and potential out-of-bounds write issues in the Linux kernel.
To resolve CVE-2021-3501, upgrade the Linux kernel to version 5.12 or later or apply the relevant patches provided by your distribution.
CVE-2021-3501 affects Linux kernel versions before 5.12, including specific Red Hat and Debian kernels.
Systems running vulnerable versions of the Linux kernel, such as earlier versions of Red Hat Enterprise Linux and Debian, are primarily impacted by CVE-2021-3501.
CVE-2021-3501 can potentially be exploited by local users with sufficient privileges to manipulate memory and cause an out-of-bounds write.