Rewterz
Rewterz Threat Advisory – ICS : Multiple Siemens Vulnerabilities
September 16, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-41079 – Apache Tomcat Vulnerability
September 16, 2021

Rewterz Threat Advisory – Multiple Linux Kernel Security Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-38300

Linux Kernel could allow a locally authenticated attacker to gain elevated privileges on the system, caused by an incorrect branches issue in the cBPF JIT compiler for MIPS. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges to execute arbitrary code in the kernel.

CVE-2021-3752

Linux Kernel is vulnerable to a denial of service, caused by a use-after-free flaw in the Bluetooth module. By sending a specially-crafted payload, a remote attacker could exploit this vulnerability to cause a denial of service condition.

Impact

  • Code Execution
  • Privilege Escalation
  • Denial of Service
  • Unauthorized Access

Affected Vendors

  • Linux

Affected Products

  • Linux Kernel

Remediation

Refer to the Linux Kernel Website for the patch, upgrade, or suggested workaround information.

https://www.kernel.org/