CVE-2021-38160

HIGHCVSS 7.8/10EPSS 0.40%

Last modified

CVE-2021-38160 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior. EPSS estimates a 0.40% chance of exploitation in the next 30 days.

Description

In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.40%

31.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LinuxLinux Kernel>= 2.6.24, < 4.4.276
LinuxLinux Kernel>= 4.5, < 4.9.276
LinuxLinux Kernel>= 4.10, < 4.14.240
LinuxLinux Kernel>= 4.15, < 4.19.198
LinuxLinux Kernel>= 4.20, < 5.4.134
LinuxLinux Kernel>= 5.5, < 5.10.52
LinuxLinux Kernel>= 5.11, < 5.12.19
LinuxLinux Kernel>= 5.13, < 5.13.4
NetappHci Bootstrap OsAll versions
NetappHci Management NodeAll versions
NetappSolidfireAll versions
NetappElement SoftwareAll versions
DebianDebian Linux9.0
DebianDebian Linux10.0
RedhatEnterprise Linux8.0

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2021-38160?
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior
How severe is CVE-2021-38160?
CVE-2021-38160 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.40% probability of exploitation in the next 30 days.
How do I fix CVE-2021-38160?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-38160?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST