cbcvebase.
CVE-2021-20261
published 2021-03-11

CVE-2021-20261: A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the…

PriorityP429medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.23%
13.4th percentile
A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the fact that the default permissions on the floppy device (/dev/fd0) are restricted to root. If the permissions on the device have changed the impact changes greatly. In the default configuration root (or equivalent) permissions are required to attack this flaw.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.5.1-1 (bookworm)linux 4.5.1-1 (bookworm)
linuxlinux_kernel< 4.54.5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 4.5.1-14.5.1-1
linuxlinux_kernel>= 0 < 4.5.1-14.5.1-1
linuxlinux_kernel>= 0 < 4.5.1-14.5.1-1
linuxlinux_kernel>= 0 < 4.5.1-14.5.1-1
linuxlinux_kernel>= 0 < 4.4.0-208.2404.4.0-208.240
redhatenterprise_linux

CVSS provenance

nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.