Rewterz
Rewterz Threat Advisory – CVE-2021-1420 – Cisco Webex Meetings HTML Injection Vulnerability
April 8, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-1479 – Cisco SD-WAN vManage Software buffer overflow
April 8, 2021

Rewterz Threat Advisory – CVE-2021-3483 – Linux Kernel code execution

Severity

High

Analysis Summary

CVE-2021-3483

Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a use-after-free flaw in nosy driver in Linux/drivers/firewire/nosy.c. By sending a specially-crafted ioctl call with NOSY_IOC_START command, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.

Impact

Unauthorized Access

Affected Vendors

Linux

Affected Products

Linux Kernel 5.11

Remediation

Refer to Linux Kernel GIT Repository for patch, upgrade or suggested workaround information.

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=829933ef05a951c8ff140e814656d73e74915faf