CVE-2021-1367
published 2021-02-24CVE-2021-1367: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial…
PriorityP420medium4.3CVSS 3.1
AVAACLPRNUINSUCNINAL
EPSS
0.39%
31.7th percentile
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an affected device. A successful exploit could allow the attacker to cause a traffic loop, resulting in a DoS condition.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat7.1HIGH
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47335 [MEDIUM] CWE-416 kernel: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances
kernel: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances
As syzbot reported, there is an use-after-free issue during f2fs recovery:
Use-after-free write at 0xffff88823bc16040 (in kfence-#10):
kmem_cache_destroy+0x1f/0x120 mm/slab_common.c:486
f2fs_recover_fsync_data+0x75b0/0x8380 fs/f2fs/recovery.c:869
f2fs_fill_super+0x9393/0xa420 fs/f2fs/super.c:3945
mount_bdev+0x26c/0x3a0 fs/super.c:1367
legacy_get_tree+0xea/0x180 fs/fs_context.c:592
vfs_get_tree+0x86/0x270 fs/super.c:1497
do_new_mount fs/namespace.c:2905 [inline]
path_mount+0x196f/0x2be0 fs/namespace.c:3235
do_mount fs/namespace.c:3248 [inline]
__do_sys_mount fs/name
Red Hat
kernel: can: mcba_usb: fix memory leak in mcba_usb
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47231 [MEDIUM] CWE-402 kernel: can: mcba_usb: fix memory leak in mcba_usb
kernel: can: mcba_usb: fix memory leak in mcba_usb
In the Linux kernel, the following vulnerability has been resolved:
can: mcba_usb: fix memory leak in mcba_usb
Syzbot reported memory leak in SocketCAN driver for Microchip CAN BUS
Analyzer Tool. The problem was in unfreed usb_coherent.
In mcba_usb_start() 20 coherent buffers are allocated and there is
nothing, that frees them:
1) In callback function the urb is resubmitted and that's all
2) In disconnect function urbs are simply killed, but URB_FREE_BUFFER
is not set (see mcba_usb_start) and this flag cannot be used with
coherent buffers.
Fail log:
| [ 1354.053291][ T8413] mcba_usb 1-1:0.0 can0: device disconnected
| [ 1367.059384][ T8420] kmemleak: 20 new suspected memory leaks (see /sys/kernel/debug/kmem)
So, all allocated buffers shou
Cisco
Cisco NX-OS Software Protocol Independent Multicast Denial of Service Vulnerability
vendor_cisco·2021-02-24·CVSS 4.3
CVE-2021-1367 [MEDIUM] CWE-20 Cisco NX-OS Software Protocol Independent Multicast Denial of Service Vulnerability
Cisco NX-OS Software Protocol Independent Multicast Denial of Service Vulnerability
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an affected device. A successful exploit could allow the attacker to cause a traffic loop, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecuri
Cisco
Cisco NX-OS Software Protocol Independent Multicast Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1367 Cisco NX-OS Software Protocol Independent Multicast Denial of Service Vulnerability
CVE-2021-1367: Cisco NX-OS Software Protocol Independent Multicast Denial of Service Vulnerability
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an affected device. A successful exploit could allow the attacker to cause a traffic loop, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-20, CWE-20
Bug IDs: CSCvv98438
GHSA
GHSA-vvw2-6xj7-ff35: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause
ghsa_unreviewed·2022-05-24
CVE-2021-1367 [MEDIUM] CWE-20 GHSA-vvw2-6xj7-ff35: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an affected device. A successful exploit could allow the attacker to cause a traffic loop, resulting in a DoS condition.
No detection rules found.
No public exploits indexed.
2021-02-24
Published