imPC@ndo IT

Tracker / CVE-2021-45485

CVE-2021-45485

High 7.5

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.

Affected products and versions

linux linux_kernel · … → 4.4.276
linux linux_kernel · 4.10 → 4.14.240
linux linux_kernel · 4.15 → 4.19.198
linux linux_kernel · 4.20 → 5.4.133
linux linux_kernel · 4.5 → 4.9.276
linux linux_kernel · 5.11 → 5.12.18
linux linux_kernel · 5.13 → 5.13.3
linux linux_kernel · 5.5 → 5.10.51
netapp aff_a400_firmware
netapp all_flash_fabric-attached_storage_8300_firmware
netapp all_flash_fabric-attached_storage_8700_firmware
netapp brocade_fabric_operating_system_firmware
netapp e-series_santricity_os_controller
netapp fabric-attached_storage_8300_firmware
netapp fabric-attached_storage_8700_firmware
netapp fabric-attached_storage_a400_firmware
netapp h300e_firmware
netapp h300s_firmware
netapp h410c_firmware
netapp h410s_firmware
netapp h500e_firmware
netapp h500s_firmware
netapp h610c_firmware
netapp h610s_firmware
netapp h615c_firmware
netapp h700e_firmware
netapp h700s_firmware
netapp hci_compute_node_firmware
netapp solidfire\,_enterprise_sds_\&_hci_storage_node
netapp solidfire_\&_hci_management_node
oracle communications_cloud_native_core_binding_support_function
oracle communications_cloud_native_core_network_exposure_function
oracle communications_cloud_native_core_policy

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References