CVE-2021-39636
published 2021-12-15CVE-2021-39636: In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local…
PriorityP415medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.22%
13.0th percentile
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.16.5-1 (bookworm) | linux 4.16.5-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.4.0-223.256 | 4.4.0-223.256 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-04-01·CVSS 5.3
CVE-2021-42739 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the VFIO PCI driver in the Linux kernel did not
properly handle attempts to access disabled memory spaces. A local attacker
could use this to cause a denial of service (system crash).
(CVE-2020-12888)
Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation did
not properly verify certain fragmented frames. A physically proximate
attacker could possibly use this issue to inject or decrypt packets.
(CVE-2020-26141)
Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation
accepted plaintext fragments in certain situations. A physically proximate
attacker could use this issue to inject packets. (CVE-2020-26145)
It was discovered that a race c
Red Hat
kernel: information disclosure due to uninitialized data in do_ipt_get_ctl() and do_ipt_set_ctl() in ip_tables.c
vendor_redhat·2021-12-06·CVSS 4.4
CVE-2021-39636 [MEDIUM] CWE-200 kernel: information disclosure due to uninitialized data in do_ipt_get_ctl() and do_ipt_set_ctl() in ip_tables.c
kernel: information disclosure due to uninitialized data in do_ipt_get_ctl() and do_ipt_set_ctl() in ip_tables.c
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel
A vulnerability was found in the Linux kernel’s net/ipv6/netfilter/ip6_tables.c:copy_entries_to_user function. This flaw allows a local attacker to leak internal kernel information.
Mitigation: To mitigate this issue, prevent the module ip6_tables from being loaded.
Please see https://access.redhat.com/solutions/41278
for i
Debian
CVE-2021-39636: linux - In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to ...
vendor_debian·2021·CVSS 4.4
CVE-2021-39636 [MEDIUM] CVE-2021-39636: linux - In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to ...
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 4.16.5-1)
bullseye: resolved (fixed in 4.16.5-1)
forky: resolved (fixed in 4.16.5-1)
sid: resolved (fixed in 4.16.5-1)
trixie: resolved (fixed in 4.16.5-1)
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2022-04-01·CVSS 5.3
CVE-2020-12888 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
It was discovered that the VFIO PCI driver in the Linux kernel did not
properly handle attempts to access disabled memory spaces. A local attacker
could use this to cause a denial of service (system crash).
(CVE-2020-12888)
Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation did
not properly verify certain fragmented frames. A physically proximate
attacker could possibly use this issue to inject or decrypt packets.
(CVE-2020-26141)
Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation
accepted plaintext fragments in certain situations. A physically proximate
attacker could use this issue to inject packets. (CVE-2020-26145)
It was discovered that a race condition existed in the Atheros Ath9k Wi
GHSA
GHSA-35xq-5wph-pxqw: In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables
ghsa_unreviewed·2021-12-16
CVE-2021-39636 [MEDIUM] CWE-909 GHSA-35xq-5wph-pxqw: In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel
OSV
CVE-2021-39636: In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables
osv·2021-12-15·CVSS 4.4
CVE-2021-39636 [MEDIUM] CVE-2021-39636: In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel
OSV
CVE-2021-39636: In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables
osv·2021-12-01
CVE-2021-39636 CVE-2021-39636: In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published