Rewterz
Rewterz Threat Advisory –Multiple IBM Security Vulnerabilities
August 10, 2021
Rewterz
Rewterz Threat Advisory –Multiple NetApp Cloud Manager Vulnerabilities
August 10, 2021

Rewterz Threat Advisory –CVE-2021-38166 – Linux Kernel Integer Overflow Vulnerability

Severity

High

Analysis Summary

CVE-2021-38166

Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by an integer overflow and out-of-bounds write when many elements are placed in a single bucket in kernel/bpf/hashtab.c. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

  • Unauthorized Access

Affected Vendors

  • Linux

Affected Products

  • Linux Kernel 5.13

Remediation

Upgrade to the latest version of Linux Kernel. available from the Linux Kernel GIT Repository.

https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=c4eb1f403243fc7bbb7de644db8587c03de36da6