CVE-2021-3743: High severity linux kernel vulnerability
An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
Other sources
An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol qrtrendpointpost in the Linux kernel. A missing sanity check may allow a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information.
References: https://lists.openwall.net/netdev/2021/08/17/124 https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=7e78c597c3eb
— Red Hat
Affected Software
Remediation
Information
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-3743?
CVE-2021-3743 has a severity rating of medium, primarily due to the potential for local attackers to exploit the out-of-bounds memory read flaw.
How do I fix CVE-2021-3743?
To remediate CVE-2021-3743, upgrade to kernel versions 0:4.18.0-372.9.1.rt7.166.el8 or 0:4.18.0-372.9.1.el8 or later, depending on your distribution.
What systems are affected by CVE-2021-3743?
CVE-2021-3743 affects several versions of the Linux kernel, particularly those between versions 5.14.1 and 5.17.
What type of vulnerability is CVE-2021-3743?
CVE-2021-3743 is classified as an out-of-bounds (OOB) memory read vulnerability within the Qualcomm IPC router protocol in the Linux kernel.
Can CVE-2021-3743 lead to remote code execution?
CVE-2021-3743 does not directly lead to remote code execution, but it can cause a system crash or leak internal kernel information.