Lucene search

K
cvelistTalosCVELIST:CVE-2021-21781
HistoryAug 18, 2021 - 2:37 p.m.

CVE-2021-21781

2021-08-1814:37:46
CWE-908
talos
www.cve.org

4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.9%

An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11

CNA Affected

[
  {
    "product": "Linux Kernel",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Linux Kernel v5.4.54, Linux Kernel v5.4.66"
      }
    ]
  }
]

4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.9%