USN-5117-1

Advisory lineage Upstream: 8 Downstream: 0
Published: 20 Oct 2021, 18:46
Last modified:14 Sept 2026, 11:16

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Oct 2021, 18:46
Published
Vulnerability first disclosed
14 Sept 2026, 11:16
Last Modified
Vulnerability information updated

Description

linux-oem-5.13 vulnerabilities It was discovered that the btrfs file system in the Linux kernel did not properly handle removing a non-existent device id. An attacker with CAP_SYS_ADMIN could use this to cause a denial of service. (CVE-2021-3739) It was discovered that the Qualcomm IPC Router protocol implementation in the Linux kernel did not properly validate metadata in some situations. A local attacker could use this to cause a denial of service (system crash) or expose sensitive information. (CVE-2021-3743) It was discovered that the virtual terminal (vt) device implementation in the Linux kernel contained a race condition in its ioctl handling that led to an out-of-bounds read vulnerability. A local attacker could possibly use this to expose sensitive information. (CVE-2021-3753) It was discovered that the Linux kernel did not properly account for the memory usage of certain IPC objects. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2021-3759)

Affected Systems

  • ubuntulinux-oem-5.13

    < 5.13.0-1017.21

References (5)