#VU92763 Improper control of generation of code ('code injection') in Linux kernel - CVE-2021-3411 

 

#VU92763 Improper control of generation of code ('code injection') in Linux kernel - CVE-2021-3411

Published: March 9, 2021 / Updated: May 21, 2021


Vulnerability identifier: #VU92763
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-3411
CWE-ID: CWE-94
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Linux kernel
Software vendor:
Linux Foundation

Description

The vulnerability allows a local privileged user to execute arbitrary code.

A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.


Remediation

Install update from vendor's repository.

External links