Back to search
CVE-2021-38160
Published: Aug 7, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.4
x_refsource_MISC
https://access.redhat.com/security/cve/cve-2021-38160
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20210902-0010/
x_refsource_CONFIRM
DSA-4978
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20211216 [SECURITY] [DLA 2843-1] linux security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now