CVE-2021-20226 log

Source
Severity Medium
Remote No
Type Privilege escalation
Description
An inappropriate handling of descriptors that results in a use-after-free vulnerability was found on the Linux kernel before version 5.10.
Group Package Affected Fixed Severity Status Ticket
AVG-1557 linux-hardened 5.9.16.a-1 5.10.a-1 Medium Not affected
AVG-1556 linux-zen 5.9.14.zen1-1 5.10.1.zen1-1 Medium Not affected
AVG-1555 linux 5.9.14.a-1 5.10.1.a-1 Medium Not affected
References
https://bugzilla.redhat.com/show_bug.cgi?id=1873476
https://seclists.org/oss-sec/2021/q1/111
https://www.zerodayinitiative.com/advisories/ZDI-21-001/
https://access.redhat.com/security/cve/CVE-2021-20226
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20226
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=233295130e53c8dfe6dbef3f52634c3f7e44cd6a