CVE-2021-0941
published 2021-10-25CVE-2021-0941: In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.16%
6.0th percentile
In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.28-1 (bookworm) | linux 5.10.28-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.28-1 | 5.10.28-1 |
| linux | linux_kernel | >= 0 < 5.10.28-1 | 5.10.28-1 |
| linux | linux_kernel | >= 0 < 5.10.28-1 | 5.10.28-1 |
| linux | linux_kernel | >= 0 < 5.10.28-1 | 5.10.28-1 |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
kernel: out-of-bounds read in bpf_skb_change_head() of filter.c due to a use-after-free
vendor_redhat·2021-02-13·CVSS 6.7
CVE-2021-0941 [MEDIUM] CWE-125 kernel: out-of-bounds read in bpf_skb_change_head() of filter.c due to a use-after-free
kernel: out-of-bounds read in bpf_skb_change_head() of filter.c due to a use-after-free
In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel
An out-of-bounds (OOB) memory access flaw was found in net/core/filter.c in __bpf_skb_max_len in the Linux kernel. A missing sanity check to the current MTU check may allow a local attacker with special user privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information.
Statement: The default Red Hat Enterprise Linux kernel
Debian
CVE-2021-0941: linux - In bpf_skb_change_head of filter.c, there is a possible out of bounds read due t...
vendor_debian·2021·CVSS 6.7
CVE-2021-0941 [MEDIUM] CVE-2021-0941: linux - In bpf_skb_change_head of filter.c, there is a possible out of bounds read due t...
In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.10.28-1)
bullseye: resolved (fixed in 5.10.28-1)
forky: resolved (fixed in 5.10.28-1)
sid: resolved (fixed in 5.10.28-1)
trixie: resolved (fixed in 5.10.28-1)
GHSA
GHSA-c5v3-wvrc-wjc5: In bpf_skb_change_head of filter
ghsa_unreviewed·2022-05-24
CVE-2021-0941 [HIGH] CWE-125 GHSA-c5v3-wvrc-wjc5: In bpf_skb_change_head of filter
In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel
OSV
CVE-2021-0941: In bpf_skb_change_head of filter
osv·2021-10-25·CVSS 6.7
CVE-2021-0941 [MEDIUM] CVE-2021-0941: In bpf_skb_change_head of filter
In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel
OSV
CVE-2021-0941: In bpf_skb_change_head of filter
osv·2021-10-01
CVE-2021-0941 CVE-2021-0941: In bpf_skb_change_head of filter
In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-25
Published