imPC@ndo IT

Tracker / CVE-2021-20292

CVE-2021-20292

Medium 6.7

There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverage this vulnerability to escalate privileges and execute code in the context of the kernel.

Affected products and versions

debian debian_linux
fedoraproject fedora
linux linux_kernel · 3.3 → 4.9.298
linux linux_kernel · 4.10 → 4.14.263
linux linux_kernel · 4.15 → 4.19.140
linux linux_kernel · 4.20 → 5.4.59
linux linux_kernel · 5.5 → 5.7.16
linux linux_kernel · 5.8 → 5.8.2
redhat enterprise_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References