CVE-2021-38160Classic Buffer Overflow in Kernel

Severity
7.8HIGHNVD
OSV6.5OSV5.5OSV4.7
EPSS
0.1%
top 77.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 7
Latest updateJun 1

Description

In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel2.6.244.4.276+7
Debianlinux/linux_kernel< 5.10.46-5+3
Ubuntulinux/linux_kernel< 4.15.0-156.163+2
debiandebian/linux< linux 5.14.6-1 (bookworm)

Also affects: Debian Linux 10.0, 9.0, Enterprise Linux 8.0

Patches

🔴Vulnerability Details

15
OSV
CVE-2021-38160: In get_inbuf and control_work_handler of virtio_console2022-06-01
GHSA
GHSA-fjw9-4q3j-vpq4: In drivers/char/virtio_console2022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22
OSV
linux-azure, linux-azure-5.11 regression2021-10-18
OSV
linux-azure, linux-azure-5.4 regression2021-10-15

📋Vendor Advisories

14
Ubuntu
Linux kernel vulnerabilities2022-03-22
Ubuntu
Linux kernel (Azure) regression2021-10-18
Ubuntu
Linux kernel (Azure) regression2021-10-15
Ubuntu
Linux kernel (OEM) vulnerabilities2021-10-06
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2021-09-30
CVE-2021-38160 — Classic Buffer Overflow in Kernel | cvebase