CVE-2021-0669
published 2021-11-18CVE-2021-0669: In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.12%
2.1th percentile
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05681550; Issue ID: ALPS05681550.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dpdk | dpdk | >= 0 < 19.11.12-0ubuntu0.20.04.1 | 19.11.12-0ubuntu0.20.04.1 |
| dpdk | dpdk | >= 0 < 21.11.1-0ubuntu0.3 | 21.11.1-0ubuntu0.3 |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r29q-cqch-x3fv: In apusys, there is a possible memory corruption due to a use after free
ghsa_unreviewed·2022-05-24
CVE-2021-0669 [HIGH] CWE-416 GHSA-r29q-cqch-x3fv: In apusys, there is a possible memory corruption due to a use after free
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05681550; Issue ID: ALPS05681550.
OSV
dpdk vulnerabilities
osv·2022-05-04·CVSS 7.5
CVE-2021-3839 dpdk vulnerabilities
dpdk vulnerabilities
Wenxiang Qian discovered that DPDK incorrectly checked certain payloads. An
attacker could use this issue to cause DPDK to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2021-3839)
It was discovered that DPDK incorrectly handled inflight type messages. An
attacker could possibly use this issue to cause DPDK to consume resources,
leading to a denial of service. (CVE-2022-0669)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-18
Published