CVE-2021-34693Missing Initialization of Resource in Linux

Severity
5.5MEDIUMNVD
OSV7.8OSV6.5OSV5.4
EPSS
0.1%
top 83.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateMay 24

Description

net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

9
GHSA
GHSA-c44h-4g88-mw48: net/can/bcm2022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-02-22
OSV
linux-raspi2 vulnerabilities2021-09-22
OSV
linux-gcp, linux-gcp-4.15 vulnerabilities2021-09-17

📋Vendor Advisories

10
Ubuntu
Linux kernel vulnerabilities2022-03-22
Ubuntu
Linux kernel vulnerabilities2022-02-22
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2021-09-22
Ubuntu
Linux kernel (GCP) vulnerabilities2021-09-17
Ubuntu
Linux kernel vulnerabilities2021-09-09

💬Community

1
Bugzilla
CVE-2021-34693 kernel: allows local users to obtain sensitive information from stack memory because of uninitialized data structure in net/can/bcm.c2021-06-15
CVE-2021-34693 — Missing Initialization of Resource | cvebase