SB2021032319 - Incorrect comparison in Linux kernel



SB2021032319 - Incorrect comparison in Linux kernel

Published: March 23, 2021

Security Bulletin ID SB2021032319
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Incorrect comparison (CVE-ID: CVE-2021-20219)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity check) and cause a threat to the system availability.


Remediation

Install update from vendor's website.