CVE-2021-3669
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
Affected (25)
Products: Linux: Linux Kernel · Ibm: Spectrum Copy Data Management, Spectrum Protect Plus · Debian: Debian Linux · +2 more
Show all products
Linux: Linux Kernel · Ibm: Spectrum Copy Data Management, Spectrum Protect Plus · Debian: Debian Linux · Fedoraproject: Fedora · Redhat: Build Of Quarkus, Developer Tools, Enterprise Linux, Enterprise Linux Aus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Real Time, Enterprise Linux For Real Time For Nfv, Enterprise Linux For Real Time For Nfv Tus, Enterprise Linux For Real Time Tus, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Codeready Linux Builder, Openshift Container Platform, Virtualization Host
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.2.0.0 to 2.2.15.0 | |
| From 10.1.0 to 10.1.10.2 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0 to 2.7 | |
| Version 1.0 | |
| Version 6.0 | |
| Version 8.6 | |
| Version 8.0 | |
| Version 8.6 | |
| Version 8 | |
| Version 8 | |
| Version 8.6 | |
| Version 8.6 | |
| Version 8.6 | |
| Version 8.6 | |
| Version 8.6 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux Eus | Version 8.6 |
Redhat Enterprise Linux For Power Little Endian | Version 8.0 |
Redhat Enterprise Linux For Power Little Endian Eus | Version 8.6 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.6 | |
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 8.0 |
Related CWEs
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CWE-770
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
References (9)
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Issue TrackingPermissions Required
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Timeline
No history available yet.