cbcvebase.
CVE-2021-26931
published 2021-02-17

CVE-2021-26931: An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.54%
42.6th percentile
An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions), it isn't correct to assume a plain bug. Memory allocations potentially causing such crashes occur only when Linux is running in PV mode, though. This affects drivers/block/xen-blkback/blkback.c and drivers/xen/xen-scsiback.c.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.10.24-1 (bookworm)linux 5.10.24-1 (bookworm)
debianlinux< linux 5.10.19-1 (bookworm)linux 5.10.19-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.24-15.10.24-1
linuxlinux_kernel>= 0 < 5.10.19-15.10.19-1
linuxlinux_kernel>= 0 < 5.10.24-15.10.24-1
linuxlinux_kernel>= 0 < 5.10.19-15.10.19-1
linuxlinux_kernel>= 0 < 5.10.24-15.10.24-1
linuxlinux_kernel>= 0 < 5.10.19-15.10.19-1
linuxlinux_kernel>= 0 < 5.10.24-15.10.24-1
linuxlinux_kernel>= 0 < 5.10.19-15.10.19-1
linuxlinux_kernel>= 0 < 4.4.0-208.2404.4.0-208.240
linuxlinux_kernel>= 0 < 4.15.0-143.1474.15.0-143.147
linuxlinux_kernel>= 0 < 5.4.0-71.795.4.0-71.79
linuxlinux_kernel>= 2.6.39 < 4.4.2604.4.260
linuxlinux_kernel2.6.39 – 5.10.16
linuxlinux_kernel>= 4.10.0 < 4.14.2244.14.224
linuxlinux_kernel>= 4.15.0 < 4.19.1794.19.179
linuxlinux_kernel>= 4.20.0 < 5.4.1035.4.103
linuxlinux_kernel>= 4.5.0 < 4.9.2604.9.260
linuxlinux_kernel>= 5.10.0 < 5.10.215.10.21
linuxlinux_kernel>= 5.11.0 < 5.11.45.11.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.