CVE-2021-3714
published 2022-08-23CVE-2021-3714: A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local…
medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| craftcms | cms | >= 3.4.0 < 3.7.14 | 3.7.14 |
| debian | linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
Red Hat
kernel: Remote Page Deduplication Attacks
vendor_redhat·2021-11-16·CVSS 5.9
CVE-2021-3714 [MEDIUM] CWE-200 kernel: Remote Page Deduplication Attacks
kernel: Remote Page Deduplication Attacks
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.
Statement: This issue affects the versions of the Linux
Debian
CVE-2021-3714: linux - A flaw was found in the Linux kernels memory deduplication mechanism. Previous w...
vendor_debian·2021·CVSS 5.9
CVE-2021-3714 [MEDIUM] CVE-2021-3714: linux - A flaw was found in the Linux kernels memory deduplication mechanism. Previous w...
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-p9ch-h5p3-4xcq: A flaw was found in the Linux kernels memory deduplication mechanism
ghsa_unreviewed·2022-08-24
CVE-2021-3714 [HIGH] CWE-200 GHSA-p9ch-h5p3-4xcq: A flaw was found in the Linux kernels memory deduplication mechanism
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.
OSV
CVE-2021-3714: A flaw was found in the Linux kernels memory deduplication mechanism
osv·2022-08-23·CVSS 5.9
CVE-2021-3714 [MEDIUM] CVE-2021-3714: A flaw was found in the Linux kernels memory deduplication mechanism
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.
GHSA
CSV Injection Vulnerability
ghsa·2021-10-18
CVE-2021-41824 [HIGH] CWE-1236 CSV Injection Vulnerability
CSV Injection Vulnerability
### Impact
In some circumstances, it was possible to export data in CSV format that could trigger a payload in old versions of Excel.
If you are accepting user input from untrusted sources and will be exporting that data in CSV format from element index pages and there is a chance users will open that on old versions of Excel, then you should update.
### Patches
This has been patched in Craft 3.7.14.
### References
* https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#3714---2021-09-28
* https://twitter.com/craftcmsupdates/status/1442928690145366018
### For more information
If you have any questions or comments about this advisory, email us at [email protected]
Credits: BAE Systems AI Vulnerability Research Team – Azrul Ikhwan Zulkifli
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2021-3714https://arxiv.org/abs/2111.08553https://arxiv.org/pdf/2111.08553.pdfhttps://bugzilla.redhat.com/show_bug.cgi?id=1931327https://access.redhat.com/security/cve/CVE-2021-3714https://arxiv.org/abs/2111.08553https://arxiv.org/pdf/2111.08553.pdfhttps://bugzilla.redhat.com/show_bug.cgi?id=1931327
2022-08-23
Published