cbcvebase.
CVE-2021-26392
published 2022-11-09

CVE-2021-26392: Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.5th percentile
Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.

Affected

15 ranges
VendorProductVersion rangeFixed in
amdamd_radeon_rx_5000_series_pro_w5000_series>= AMD Radeon Pro Software Enterprise < 22.Q222.Q2
amdamd_radeon_rx_5000_series_pro_w5000_series>= AMD Radeon Software < 22.5.222.5.2
amdamd_radeon_rx_5000_series_pro_w5000_series>= Enterprise Driver < 22.10.2022.10.20
amdamd_radeon_rx_6000_series_pro_w6000_series>= AMD Radeon Pro Software Enterprise < 22.Q222.Q2
amdamd_radeon_rx_6000_series_pro_w6000_series>= AMD Radeon Software < 22.5.222.5.2
amdamd_radeon_rx_6000_series_pro_w6000_series>= Enterprise Driver < 22.10.2022.10.20
amdamd_ryzen_embedded_5000
amdamd_ryzen_embedded_r1000
amdamd_ryzen_embedded_r2000
amdamd_ryzen_embedded_v1000
amdamd_ryzen_embedded_v2000
amdamd_ryzen_embedded_v3000
amdenterprise_driver< 22.10.2022.10.20
amdradeon_pro_software< 22.q222.q2
amdradeon_software< 22.5.222.5.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.