First published: Tue Aug 31 2021(Updated: )
A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Linux kernel | <5.15 | 5.15 |
Linux Kernel | <5.15 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp Element Software | ||
netapp hci management node | ||
netapp solidfire | ||
All of | ||
netapp bootstrap os | ||
netapp hci compute node | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
netapp bootstrap os | ||
netapp hci compute node | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h410c firmware | ||
netapp h410c | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.13-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3753 is considered high due to its impact on data confidentiality.
To fix CVE-2021-3753, update your Linux kernel to version 5.15 or apply the recommended patches for versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
CVE-2021-3753 affects various versions of the Linux kernel, including specific Red Hat Enterprise Linux and Debian packages.
CVE-2021-3753 is a race condition vulnerability that can lead to out of bounds reading in the Linux kernel.
The consequences of CVE-2021-3753 include potential unauthorized access to sensitive data due to compromised data confidentiality.