CVE-2021-38166: Integer Overflow
In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAPSYSADMIN capability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38166?
CVE-2021-38166 has a moderate severity due to the potential for integer overflow and out-of-bounds write in the Linux kernel.
How do I fix CVE-2021-38166?
To fix CVE-2021-38166, update to a patched version of the Linux kernel, specifically any version beyond 5.13.8.
Which versions of the Linux kernel are affected by CVE-2021-38166?
CVE-2021-38166 affects the Linux kernel versions up to and including 5.13.8.
Can CVE-2021-38166 be exploited without special permissions?
Exploitation of CVE-2021-38166 might be impractical without possessing the CAP_SYS_ADMIN capability.
What systems are impacted by CVE-2021-38166?
CVE-2021-38166 impacts systems running affected versions of the Linux kernel, including Fedora 33, Fedora 34, and Debian 11.0.