CVE-2021-20265

Description

A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.04

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2021:0856) kernel security and bug fix update bpftool-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-abi-whitelists-3.10.0-1160.21.1.el7.noarch.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-debug-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-debug-devel-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-devel-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-doc-3.10.0-1160.21.1.el7.noarch.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-headers-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-tools-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-tools-libs-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update kernel-tools-libs-devel-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update perf-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(RHSA-2021:0856) kernel security and bug fix update python-perf-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update bpftool-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-abi-whitelists-3.10.0-1160.21.1.el7.noarch.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-debug-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-debug-devel-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-devel-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-doc-3.10.0-1160.21.1.el7.noarch.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-headers-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-tools-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-tools-libs-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update kernel-tools-libs-devel-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update perf-3.10.0-1160.21.1.el7.x86_64.rpmLinux
(CESA-2021:0856) kernel security and bug fix update python-perf-3.10.0-1160.21.1.el7.x86_64.rpmLinux
SUSE-SU-2021:14849-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-108.132.1.i586.rpmLinux
SUSE-SU-2021:14849-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-108.132.1.x86_64.rpmLinux
SUSE-SU-2021:14849-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-pae-extra-3.0.101-108.132.1.i586.rpmLinux
SUSE-SU-2021:14849-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-trace-extra-3.0.101-108.132.1.x86_64.rpmLinux
SUSE-SU-2021:14849-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-108.132.1.i586.rpmLinux
SUSE-SU-2021:14849-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-108.132.1.x86_64.rpmLinux
Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2021-20265)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234