CVE-2021-31916

Modified
Published: 06 May 2021, 16:14
Last modified:03 Aug 2024, 23:10

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.7 MEDIUM
v3.1 (nvd)
EPSS Score
0.11% LOW
0% probability +0.08%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 May 2021, 16:14
Published
Vulnerability first disclosed
03 Aug 2024, 23:10
Last Modified
Vulnerability information updated

Description

An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.

CVSS Metrics

  • v3.1MEDIUMScore: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.1AV:L/AC:L/Au:N/C:P/I:P/A:C

EPSS Trends

Current EPSS score: 0.11% Percentile: 28%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • debiandebian_linux

    9.0

  • linuxlinux_kernel

    < 5.12

  • redhatenterprise_linux

    7.0 | 8.0

References (5)