Description
An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2713-1 | linux security update |
Debian DLA |
DLA-2713-2 | linux security update |
EUVD |
EUVD-2021-8953 | An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11 |
References
History
No history.
Subscriptions
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-03T18:23:29.351Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21781
No data.
Status : Modified
Published: 2021-08-18T15:15:07.733
Modified: 2024-11-21T05:48:57.427
Link: CVE-2021-21781
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD