Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2021.0295
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2021-0295)
Summary:The remote host is missing an update for the 'kernel-linus' package(s) announced via the MGASA-2021-0295 advisory.
Description:Summary:
The remote host is missing an update for the 'kernel-linus' package(s) announced via the MGASA-2021-0295 advisory.

Vulnerability Insight:
This kernel-linus update is based on upstream 5.10.46 and fixes at least
the following security issues:

In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can
be mispredicted (e.g., because of type confusion) and consequently an
unprivileged BPF program can read arbitrary memory locations via a
side-channel attack (CVE-2021-33624).

net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to
obtain sensitive information from kernel stack memory because parts of a
data structure are uninitialized. (CVE-2021-34693).

For other upstream fixes, see the referenced changelog.

Affected Software/OS:
'kernel-linus' package(s) on Mageia 7, Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
4.7

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-33624
https://www.usenix.org/conference/usenixsecurity21/presentation/kirzner
https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-34693
Debian Security Information: DSA-4941 (Google Search)
https://www.debian.org/security/2021/dsa-4941
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5e87ddbe3942e27e939bdc02deb8579b0cbd8ecc
https://lore.kernel.org/netdev/trinity-87eaea25-2a7d-4aa9-92a5-269b822e5d95-1623609211076@3c-app-gmx-bs04/T/
https://lists.debian.org/debian-lts-announce/2021/07/msg00014.html
https://lists.debian.org/debian-lts-announce/2021/07/msg00016.html
https://lists.debian.org/debian-lts-announce/2021/07/msg00015.html
http://www.openwall.com/lists/oss-security/2021/06/15/1
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.