CVE-2021-3543 - log back

CVE-2021-3543 edited at 18 May 2021 07:01:15
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Privilege escalation
Description
+ A null pointer dereference in the Nitro Enclaves Linux kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1953022
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.3&id=3494c68d79cbb7ddff88fd35e0796343ef736606
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.20&id=5f4a8ccfc15c1498d897139e5dbff82a35005144
+ https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.36&id=ed9cfd60c7875b0597e672e89c0bad09a88307d2
CVE-2021-3543 created at 18 May 2021 06:58:03
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes