Skip to content

kernel CVE-2021-3348

Moderate
tjkirch published GHSA-qrpq-fg62-m5cm Mar 2, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.0.6

Patched versions

1.0.6

Description

A use-after-free flaw was found in nbd_add_socket in drivers/block/nbd.c that could be triggered by local attackers with access to the nbd device via an I/O request at a certain point during device setup.

Severity

Moderate

CVE ID

CVE-2021-3348

Weaknesses

No CWEs