First published: Tue Aug 31 2021(Updated: )
A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Linux kernel | <5.15 | 5.15 |
Linux Kernel | <5.15 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp Management Services for Element Software | ||
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
NetApp HCI Bootstrap OS | ||
NetApp HCI Compute Node | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
All of | ||
NetApp HCI Bootstrap OS | ||
NetApp HCI Compute Node | ||
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
All of | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3753 is considered high due to its impact on data confidentiality.
To fix CVE-2021-3753, update your Linux kernel to version 5.15 or apply the recommended patches for versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
CVE-2021-3753 affects various versions of the Linux kernel, including specific Red Hat Enterprise Linux and Debian packages.
CVE-2021-3753 is a race condition vulnerability that can lead to out of bounds reading in the Linux kernel.
The consequences of CVE-2021-3753 include potential unauthorized access to sensitive data due to compromised data confidentiality.