CVE-2021-3347
Summary
| CVE | CVE-2021-3347 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-29 17:15:00 UTC |
| Updated | 2023-11-07 03:37:00 UTC |
| Description | An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458. |
Risk And Classification
Problem Types: CWE-416
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: Linux Kernel: local priv escalation via futexes | MISC | www.openwall.com | Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2557-1] linux-4.19 security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| [SECURITY] [DLA 2586-1] linux security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| CVE-2021-3347 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| oss-security - Linux Kernel: local priv escalation via futexes | MISC | www.openwall.com | Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| oss-security - Re: Linux Kernel: local priv escalation via futexes | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4843-1 linux | DEBIAN | www.debian.org | Third Party Advisory |
| [SECURITY] Fedora 32 Update: kernel-5.10.12-100.fc32 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| oss-security - Re: Linux Kernel: local priv escalation via futexes | MLIST | www.openwall.com | Exploit, Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| [SECURITY] Fedora 32 Update: kernel-5.10.12-100.fc32 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 33 Update: kernel-5.10.12-200.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| oss-security - Re: Linux Kernel: local priv escalation via futexes | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| [SECURITY] Fedora 33 Update: kernel-5.10.12-200.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159144 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-1093)
- 159258 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-2314)
- 159373 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-9434)
- 174805 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP2) (SUSE-SU-2021:0849-1)
- 174807 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 7 for SLE 15 SP2) (SUSE-SU-2021:0842-1)
- 174808 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP2) (SUSE-SU-2021:0870-1)
- 174809 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP2) (SUSE-SU-2021:0849-1)
- 174810 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (SUSE-SU-2021:0853-1)
- 174811 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP2) (SUSE-SU-2021:0840-1)
- 174812 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP1) (SUSE-SU-2021:0859-1)
- 174813 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 5 for SLE 12 SP5) (SUSE-SU-2021:0818-1)
- 174817 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 8 for SLE 15 SP2) (SUSE-SU-2021:0841-1)
- 174818 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 14 for SLE 12 SP5) (SUSE-SU-2021:0809-1)
- 174819 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 18 for SLE 15) (SUSE-SU-2021:0868-1)
- 179735 Debian Security Update for linux (CVE-2021-3347)
- 198297 Ubuntu Security Notification for Linux, Linux-aws, Linux-aws-5.4, Linux-azure, Linux-azure-5.4, Linux-gcp, (USN-4878-1)
- 198304 Ubuntu Security Notification for Linux-oem-5.10 Vulnerabilities (USN-4884-1)
- 198324 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4907-1)
- 198326 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4910-1)
- 239202 Red Hat Update for kernel (RHSA-2021:1093)
- 239204 Red Hat Update for kernel-rt (RHSA-2021:1081)
- 239236 Red Hat Update for kpatch-patch (RHSA-2021:1295)
- 239238 Red Hat Update for kernel (RHSA-2021:1272)
- 239253 Red Hat Update for kernel-alt (RHSA-2021:1379)
- 239271 Red Hat Update for kernel-alt (RHSA-2021:1379)
- 239349 Red Hat Update for kernel (RHSA-2021:2106)
- 239351 Red Hat Update for kpatch-patch (RHSA-2021:2099)
- 239403 Red Hat Update for kernel (RHSA-2021:2314)
- 239413 Red Hat Update for kpatch-patch (RHSA-2021:2285)
- 239452 Red Hat Update for kernel-rt (RHSA-2021:2316)
- 239455 Red Hat Update for kernel-rt (RHSA-2021:1279)
- 257092 CentOS Security Update for kernel (CESA-2021:2314)
- 352327 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-041
- 352328 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-040
- 352329 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-039
- 353131 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2022-020
- 377055 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2021:0027)
- 610357 Google Android Devices August 2021 Security Patch Missing
- 6140187 AWS Bottlerocket Security Update for kernel (GHSA-mq26-2rrr-55xf)
- 670345 EulerOS Security Update for kernel (EulerOS-SA-2021-1879)
- 670375 EulerOS Security Update for kernel (EulerOS-SA-2021-1950)
- 670396 EulerOS Security Update for kernel (EulerOS-SA-2021-1929)
- 670634 EulerOS Security Update for kernel (EulerOS-SA-2021-2392)
- 670744 EulerOS Security Update for kernel (EulerOS-SA-2021-2502)
- 670936 EulerOS Security Update for kernel (EulerOS-SA-2021-1929)
- 671047 EulerOS Security Update for kernel (EulerOS-SA-2021-2588)
- 730228 McAfee Web Gateway Multiple Vulnerabilities (WP-3445, WP-3483, WP-3527, WP-3528, WP-3547, WP-3584,WP-3589,WP-3611)
- 750373 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:0241-1)
- 900098 CBL-Mariner Linux Security Update for kernel 5.4.91
- 902971 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3837)
- 940387 AlmaLinux Security Update for kernel (ALSA-2021:1093)