First published: Thu Sep 30 2021(Updated: )
An out-of-bounds (OOB) memory write flaw was found in prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the bpf iin the Linux kernel. In this flaw, the multiplication to calculate the size could lead to an integer overflow, and this could allow a local attacker, with a special user privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. Reference and upstream patch: <a href="https://github.com/torvalds/linux/commit/30e29a9a2bc6a4888335a6ede968b75cd329657a">https://github.com/torvalds/linux/commit/30e29a9a2bc6a4888335a6ede968b75cd329657a</a>
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-372.9.1.rt7.166.el8 | 0:4.18.0-372.9.1.rt7.166.el8 |
redhat/kernel | <0:4.18.0-372.9.1.el8 | 0:4.18.0-372.9.1.el8 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
Linux Kernel | <5.14.12 | |
Fedora | =33 | |
Fedora | =34 | |
Fedora | =35 | |
netapp cloud backup | ||
netapp hci management node | ||
netapp solidfire | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h300e firmware | ||
netapp h300e | ||
All of | ||
netapp h500e firmware | ||
netapp h500e | ||
All of | ||
netapp h700e firmware | ||
netapp h700e | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp solidfire baseboard management controller firmware | ||
netapp solidfire baseboard management controller | ||
Debian | =9.0 | |
Debian | =10.0 | |
netapp h410c firmware | ||
netapp h410c | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h300e firmware | ||
netapp h300e | ||
netapp h500e firmware | ||
netapp h500e | ||
netapp h700e firmware | ||
netapp h700e | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp solidfire baseboard management controller firmware | ||
netapp solidfire baseboard management controller |
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41864 has a high severity rating due to its potential for exploitation leading to significant impacts on affected systems.
To fix CVE-2021-41864, update to the patched versions of the affected packages, specifically kernel-rt and kernel packages under Red Hat, or update your Linux kernel to versions beyond 5.14.12.
CVE-2021-41864 affects various distributions of the Linux kernel and specific versions of the NetApp cloud backup solutions.
CVE-2021-41864 can be exploited by local attackers with special privileges to perform out-of-bounds memory writes, potentially leading to escalation of privileges.
Yes, CVE-2021-41864 is a vulnerability within the Linux kernel, specifically in the BPF subsystem.