CVE-2021-20265
published 2021-03-10CVE-2021-20265: A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.34%
26.0th percentile
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.4.4-1 (bookworm) | linux 4.4.4-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.4.4-1 | 4.4.4-1 |
| linux | linux_kernel | >= 0 < 4.4.4-1 | 4.4.4-1 |
| linux | linux_kernel | >= 0 < 4.4.4-1 | 4.4.4-1 |
| linux | linux_kernel | >= 0 < 4.4.4-1 | 4.4.4-1 |
| oracle | tekelec_platform_distribution | 7.4.0 – 7.7.1 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-20265: linux - A flaw was found in the way memory resources were freed in the unix_stream_recvm...
vendor_debian·2021·CVSS 5.5
CVE-2021-20265 [MEDIUM] CVE-2021-20265: linux - A flaw was found in the way memory resources were freed in the unix_stream_recvm...
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 4.4.4-1)
bullseye: resolved (fixed in 4.4.4-1)
forky: resolved (fixed in 4.4.4-1)
sid: resolved (fixed in 4.4.4-1)
trixie: resolved (fixed in 4.4.4-1)
Red Hat
kernel: increase slab leak leads to DoS
vendor_redhat·2016-01-24·CVSS 5.5
CVE-2021-20265 [MEDIUM] CWE-400 kernel: increase slab leak leads to DoS
kernel: increase slab leak leads to DoS
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria c
GHSA
GHSA-7j7j-cjf4-3c2x: A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending
ghsa_unreviewed·2022-05-24
CVE-2021-20265 [MEDIUM] CWE-400 GHSA-7j7j-cjf4-3c2x: A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-20265: A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending
osv·2021-03-10·CVSS 5.5
CVE-2021-20265 [MEDIUM] CVE-2021-20265: A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1908827https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fa0dc04df259ba2df3ce1920e9690c7842f8fa4bhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1908827https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fa0dc04df259ba2df3ce1920e9690c7842f8fa4bhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-10
Published