Vulnerabilities > CVE-2021-31916 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 6.1 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
COMPLETE
local
low complexity
linux
redhat
debian
CWE-787

Summary

An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.

Vulnerable Configurations

Part Description Count
OS
Linux
3693
OS
Redhat
2
OS
Debian
1

Common Weakness Enumeration (CWE)