CVE-2021-3506: High severity Linux Linux kernel vulnerability
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
Other sources
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.12.0 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3506?
CVE-2021-3506 is considered a high severity vulnerability due to its potential to allow local attackers to gain access to sensitive memory and cause system crashes.
How do I fix CVE-2021-3506?
To fix CVE-2021-3506, upgrade to kernel version 5.12.0-rc4 or later for the Linux kernel.
Which Linux kernel versions are affected by CVE-2021-3506?
CVE-2021-3506 affects Linux kernel versions prior to 5.12.0-rc4.
Is CVE-2021-3506 exploitable remotely?
No, CVE-2021-3506 is not remotely exploitable and requires local access to the system.
What impact does CVE-2021-3506 have on the system?
The impact of CVE-2021-3506 includes the potential for system crashes and leakage of internal kernel information due to out-of-bounds memory access.