SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-20265

This flaw allows an unprivileged local user to crash the system by exhausting available memory.

MEDIUM 5.5EPSS 0.34%

Does this matter?

Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.34% probability · 27th percentile
CISA KEV
Not listed
Weakness
CWE-400, CWE-401
Affected
linux/linux kernel · oracle/tekelec platform distribution
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.