Skip to content

kernel CVE-2021-3501

High
tjkirch published GHSA-57hf-5hq2-ff32 Jun 25, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.1.2

Patched versions

1.1.2

Description

The value of internal.ndata in the KVM API is mapped to an array index, which can be updated by a user process at any time, which could lead to an out-of-bounds write.

Severity

High

CVE ID

CVE-2021-3501

Weaknesses

No CWEs