CVE-2021-20261

Description

A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the fact that the default permissions on the floppy device (/dev/fd0) are restricted to root. If the permissions on the device have changed the impact changes greatly. In the default configuration root (or equivalent) permissions are required to attack this flaw.

Risk Information

Base Score
6.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.033

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-4904-1) linux-image-aws_4.4.0.1126.131_amd64.debLinux
Linux kernel (USN-4904-1) linux-image-kvm_4.4.0.1091.89_amd64.debLinux
Linux kernel (USN-4904-1) linux-image-generic_4.4.0.208.214_i386.debLinux
Linux kernel (USN-4904-1) linux-image-generic_4.4.0.208.214_amd64.debLinux
Linux kernel (USN-4904-1) linux-image-virtual_4.4.0.208.214_i386.debLinux
Linux kernel (USN-4904-1) linux-image-virtual_4.4.0.208.214_amd64.debLinux
Linux kernel (USN-4904-1) linux-image-lowlatency_4.4.0.208.214_i386.debLinux
Linux kernel (USN-4904-1) linux-image-lowlatency_4.4.0.208.214_amd64.debLinux
Linux kernel (USN-4904-1) linux-image-4.4.0-1091-kvm_4.4.0-1091.100_amd64.debLinux
Linux kernel (USN-4904-1) linux-image-4.4.0-1126-aws_4.4.0-1126.140_amd64.debLinux
Linux kernel (USN-4904-1) linux-image-4.4.0-208-generic_4.4.0-208.240_i386.debLinux
Linux kernel (USN-4904-1) linux-image-4.4.0-208-generic_4.4.0-208.240_amd64.debLinux
Linux kernel (USN-4904-1) linux-image-4.4.0-208-lowlatency_4.4.0-208.240_i386.debLinux
Linux kernel (USN-4904-1) linux-image-4.4.0-208-lowlatency_4.4.0-208.240_amd64.debLinux
Kernel-uek update (ELSA-2021-9215) kernel-uek-4.1.12-124.50.2.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9215) kernel-uek-debug-4.1.12-124.50.2.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9215) kernel-uek-debug-devel-4.1.12-124.50.2.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9215) kernel-uek-devel-4.1.12-124.50.2.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9215) kernel-uek-doc-4.1.12-124.50.2.el7uek.noarch.rpmLinux
Kernel-uek-firmware update (ELSA-2021-9215) kernel-uek-firmware-4.1.12-124.50.2.el7uek.noarch.rpmLinux
SUSE-SU-2021:14724-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-108.126.1.i586.rpmLinux
SUSE-SU-2021:14724-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-108.126.1.x86_64.rpmLinux
SUSE-SU-2021:14724-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-pae-extra-3.0.101-108.126.1.i586.rpmLinux
SUSE-SU-2021:14724-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-trace-extra-3.0.101-108.126.1.x86_64.rpmLinux
SUSE-SU-2021:14724-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-108.126.1.i586.rpmLinux
SUSE-SU-2021:14724-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-108.126.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234