Thursday, September 9, 2021

Centos Linux: CVE-2021-3715: Moderate: kernel security and bug fix update (Multiple Advisories)

Description
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Solution(s)
  • centos-upgrade-kernel
  • centos-upgrade-kernel-rt
  • centos-upgrade-kpatch-patch-3_10_0-1160
  • centos-upgrade-kpatch-patch-3_10_0-1160-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_11_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_11_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_15_2
  • centos-upgrade-kpatch-patch-3_10_0-1160_15_2-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_21_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_21_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_24_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_24_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_25_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_25_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_2_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_2_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_2_2
  • centos-upgrade-kpatch-patch-3_10_0-1160_2_2-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_31_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_31_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_36_2
  • centos-upgrade-kpatch-patch-3_10_0-1160_36_2-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_41_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_41_1-debuginfo
  • centos-upgrade-kpatch-patch-3_10_0-1160_6_1
  • centos-upgrade-kpatch-patch-3_10_0-1160_6_1-debuginfo


  • References
  • CESA-2021:3438
  • CESA-2021:3439
  • CESA-2021:3441
  • CVE-2021-3715




  •  

    Copyright © 2021 Vulnerability Database | Cyber Details™

    thank you Templateism for the design - You should have written the code a little more complicated - Nothing Encrypted anymore