CVE-2021-38209
Summary
| CVE | CVE-2021-38209 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-08 20:15:00 UTC |
| Updated | 2021-08-12 22:49:00 UTC |
| Description | net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, and NF_SYSCTL_CT_BUCKETS sysctls. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Linux |
Linux Kernel |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| netfilter: conntrack: Make global sysctls readonly in non-init netns · torvalds/linux@2671fa4 · GitHub |
MISC |
github.com |
|
| cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.2 |
MISC |
cdn.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180014 Debian Security Update for linux (CVE-2021-38209)
- 671219 EulerOS Security Update for kernel (EulerOS-SA-2022-1030)
- 671225 EulerOS Security Update for kernel (EulerOS-SA-2022-1010)
- 671282 EulerOS Security Update for kernel (EulerOS-SA-2022-1255)
- 671436 EulerOS Security Update for kernel (EulerOS-SA-2022-1352)
- 671703 EulerOS Security Update for kernel (EulerOS-SA-2022-1735)
- 751160 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3179-1)
- 751170 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3205-1)
- 900294 CBL-Mariner Linux Security Update for kernel 5.10.52.1
- 900304 CBL-Mariner Linux Security Update for kernel 5.10.57.1
- 900319 CBL-Mariner Linux Security Update for kernel 5.10.60.1
- 901003 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (6593-1)
- 903006 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (5084)
- 905969 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (5084-1)