CVE-2021-3635
published 2021-08-13CVE-2021-3635: A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system…
medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.4.19-1 (bookworm) | linux 5.4.19-1 (bookworm) |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | < 5.5 | 5.5 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.4MEDIUM
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
kernel: flowtable list del corruption with kernel BUG at lib/list_debug.c:50
vendor_redhat·2021-08-06·CVSS 4.4
CVE-2021-3635 [MEDIUM] CWE-119 kernel: flowtable list del corruption with kernel BUG at lib/list_debug.c:50
kernel: flowtable list del corruption with kernel BUG at lib/list_debug.c:50
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
A flaw was found in the Linux kernel netfilter implementation. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands
Mitigation: Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enter
Debian
CVE-2021-3635: linux - A flaw was found in the Linux kernel netfilter implementation in versions prior ...
vendor_debian·2021·CVSS 4.4
CVE-2021-3635 [MEDIUM] CVE-2021-3635: linux - A flaw was found in the Linux kernel netfilter implementation in versions prior ...
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
Scope: local
bookworm: resolved (fixed in 5.4.19-1)
bullseye: resolved (fixed in 5.4.19-1)
forky: resolved (fixed in 5.4.19-1)
sid: resolved (fixed in 5.4.19-1)
trixie: resolved (fixed in 5.4.19-1)
OSV
CVE-2021-3635: In nft_flush_table of nf_tables_api
osv·2022-06-01
CVE-2021-3635 CVE-2021-3635: In nft_flush_table of nf_tables_api
In nft_flush_table of nf_tables_api.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
GHSA
GHSA-3rcv-mwcm-8g8f: A flaw was found in the Linux kernel netfilter implementation in versions prior to 5
ghsa_unreviewed·2022-05-24
CVE-2021-3635 [MEDIUM] CWE-119 GHSA-3rcv-mwcm-8g8f: A flaw was found in the Linux kernel netfilter implementation in versions prior to 5
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
OSV
CVE-2021-3635: A flaw was found in the Linux kernel netfilter implementation in versions prior to 5
osv·2021-08-13·CVSS 4.4
CVE-2021-3635 [MEDIUM] CVE-2021-3635: A flaw was found in the Linux kernel netfilter implementation in versions prior to 5
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-13
Published