CVE-2021-20317
Published on: 09/27/2021 12:00:00 AM UTC
Last Modified on: 06/14/2022 11:15:00 AM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP.
- CVE-2021-20317 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 4.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 4.9 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
kernel/git/tip/tip.git - Unnamed repository; edit this file 'description' to name the repository. | git.kernel.org text/html |
![]() |
[SECURITY] [DLA 2941-1] linux-4.19 security update | lists.debian.org text/html |
![]() |
cert-portal.siemens.com application/pdf |
![]() | |
2005258 – (CVE-2021-20317) CVE-2021-20317 kernel: timer tree corruption leads to missing wakeup and system freeze | bugzilla.redhat.com text/html |
![]() |
Debian -- Security Information -- DSA-5096-1 linux | www.debian.org Depreciated Link text/html |
![]() |
[SECURITY] [DLA 2843-1] linux security update | lists.debian.org text/html |
![]() |
Related QID Numbers
- 159535 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-4647)
- 159760 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2022-9314)
- 159763 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-9313)
- 178943 Debian Security Update for linux (DLA 2843-1)
- 179117 Debian Security Update for linux (DSA 5096-1)
- 179119 Debian Security Update for linux-4.19 (DLA 2941-1)
- 179946 Debian Security Update for linux (CVE-2021-20317)
- 198617 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5209-1)
- 239884 Red Hat Update for kernel (RHSA-2021:4647)
- 239887 Red Hat Update for kernel-rt (RHSA-2021:4648)
- 239890 Red Hat Update for kernel security (RHSA-2021:4650)
- 239892 Red Hat Update for kernel-rt (RHSA-2021:4646)
- 239917 Red Hat Update for kernel (RHSA-2021:4871)
- 239918 Red Hat Update for kernel-rt (RHSA-2021:4875)
- 352869 Amazon Linux Security Advisory for kernel: ALAS2-2021-1719
- 353242 Amazon Linux Security Advisory for kernel : ALAC2012-2022-036
- 353243 Amazon Linux Security Advisory for kmod-mlx5 : ALAC2012-2022-037
- 353244 Amazon Linux Security Advisory for kmod-sfc : ALAC2012-2022-038
- 590976 Siemens SCALANCE LPE9403 Third-Party Multiple Vulnerabilities (ICSA-22-167-09) (SSA-222547)
- 940174 AlmaLinux Security Update for kernel (ALSA-2021:4647)
- 960003 Rocky Linux Security Update for kernel-rt (RLSA-2021:4646)
- 960094 Rocky Linux Security Update for kernel (RLSA-2021:4647)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Debian | Debian Linux | 9.0 | All | All | All |
Operating System | Linux | Linux Kernel | All | All | All | All |
Operating System | Linux | Linux Kernel | 5.4 | - | All | All |
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:5.4:-:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-20317 : A flaw was found in the #Linux #kernel. A corrupted timer tree caused the task wakeup to be missin… twitter.com/i/web/status/1… | 2021-09-27 11:07:55 |
![]() |
DSM Version: 7.1.1-42951 (Release Candidate) | 2022-08-10 06:07:14 |
![]() |
Has anyone seen the release notes for the latest DSM 7.1.1 Release Candidate. Fixes a scary amount of CVEs. | 2022-08-16 14:26:29 |
![]() |
DSM 7.1.1-42962 released! | 2022-09-05 11:39:36 |
![]() |
ADM 4.1.0.RLQ1 update available (2022-09-28) | 2022-10-08 04:00:04 |