Back to search
CVE-2021-35039
Published: Jul 7, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.openwall.com/lists/oss-security/2021/07/06/3
x_refsource_MISC
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.14
x_refsource_CONFIRM
[oss-security] 20210706 CVE-2021-35039: Linux kernel loading unsigned kernel modules via init_module syscall
mailing-list
x_refsource_MLIST
https://security.netapp.com/advisory/ntap-20210813-0004/
x_refsource_CONFIRM
[debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now