Severity
High
Analysis Summary
CVE-2021-38166
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by an integer overflow and out-of-bounds write when many elements are placed in a single bucket in kernel/bpf/hashtab.c. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Impact
- Unauthorized Access
Affected Vendors
- Linux
Affected Products
- Linux Kernel 5.13
Remediation
Upgrade to the latest version of Linux Kernel. available from the Linux Kernel GIT Repository.