| Vulnerability Name: | CVE-2021-20269 (CCN-198071) | ||||||||||||||||||
| Assigned: | 2020-12-17 | ||||||||||||||||||
| Published: | 2021-03-02 | ||||||||||||||||||
| Updated: | 2023-02-12 | ||||||||||||||||||
| Summary: | A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47. | ||||||||||||||||||
| CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
4.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
4.2 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||
| Vulnerability Type: | CWE-276 | ||||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2021-20269 Source: secalert@redhat.com Type: Issue Tracking, Third Party Advisory secalert@redhat.com Source: CCN Type: Red Hat Bugzilla - Bug 1934261 (CVE-2021-20269) - CVE-2021-20269 kernel: incorrect permissions on kdump dmesg file Source: XF Type: UNKNOWN linux-kernel-cve202120269-info-disc(198071) Source: CCN Type: oss-sec Mailing List, Thu, 11 Mar 2021 17:19:44 +1000 CVE-2021-20269: kexec-tools: incorrect permissions on vmcore-dmesg.txt file Source: CCN Type: IBM Security Bulletin 6593539 (Spectrum Copy Data Management) Vulnerabilities in the Linux Kernel affect IBM Spectrum Copy Data Management Source: CCN Type: IBM Security Bulletin 6596971 (Spectrum Protect Plus) Multiple vulnerabilities in Linux Kernel affect IBM Spectrum Protect Plus Source: CCN Type: Linux Kernel Web site The Linux Kernel Archives | ||||||||||||||||||
| Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||
| Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
| BACK | |||||||||||||||||||