CVE-2021-20261
Published Mar 11, 2021
Last updated 4 years ago
Overview
- Description
- A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the fact that the default permissions on the floppy device (/dev/fd0) are restricted to root. If the permissions on the device have changed the impact changes greatly. In the default configuration root (or equivalent) permissions are required to attack this flaw.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.4
- Impact score
- 5.9
- Exploitability score
- 0.5
- Vector string
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.4
- Impact score
- 6.4
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- secalert@redhat.com
- CWE-362
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E422399C-2CB8-4293-9B4F-FD5703C1BA97", "versionEndExcluding": "4.5" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:4.5:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28316352-6847-4D33-8E69-F3C933F42A04" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:4.5:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5011ED56-97F0-4754-9C98-B28B806DF6DD" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:4.5:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7FC0A28-90D9-4DF3-8A2A-49C3D4CB470A" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:4.5:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D90B29E-F7B6-4EAB-83D2-1C339310D34D" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:4.5:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02A2E198-C184-459C-9B7C-8A9C74A6DCEE" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A" } ], "operator": "OR" } ] } ]