Vulnerability Name:

CVE-2021-21781 (CCN-204429)

Assigned:2021-06-25
Published:2021-06-25
Updated:2023-02-03
Summary:An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11
CVSS v3 Severity:3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
4.0 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
3.5 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-908
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-21781

Source: XF
Type: UNKNOWN
linux-kernel-cve202121781-info-disc(204429)

Source: CCN
Type: Linux Kernel GIT Repository
Linux Kernel

Source: CCN
Type: Talos Vulnerability Report TALOS-2021-1243
Linux Kernel Arm SIGPAGE information disclosure vulnerability

Source: talos-cna@cisco.com
Type: Exploit, Third Party Advisory
talos-cna@cisco.com

Source: CCN
Type: IBM Security Bulletin 6596971 (Spectrum Protect Plus)
Multiple vulnerabilities in Linux Kernel affect IBM Spectrum Protect Plus

Source: talos-cna@cisco.com
Type: Patch, Third Party Advisory
talos-cna@cisco.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:5.4.66:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:5.4.54:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:spectrum_protect_plus:10.1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8029
    P
    kernel-docs-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7571
    P
    libXvnc1-1.12.0-150500.2.6 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8090
    P
    reiserfs-kmp-default-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7585
    P
    libcroco-0.6.13-150400.9.5 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7708
    P
    libzip-devel-1.8.0-150400.1.7 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7539
    P
    kernel-64kb-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:751
    P
    Security update for bluez (Important)
    2022-09-12
    oval:org.opensuse.security:def:6132
    P
    Security update for wavpack (Low)
    2022-08-05
    oval:org.opensuse.security:def:95352
    P
    Security update for java-1_8_0-openjdk (Important) (in QA)
    2022-08-04
    oval:org.opensuse.security:def:6126
    P
    Security update for mokutil (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:3652
    P
    Security update for git (Important)
    2022-07-26
    oval:org.opensuse.security:def:95347
    P
    Security update for php7 (Important)
    2022-07-06
    oval:org.opensuse.security:def:3567
    P
    libXtst6-1.2.2-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3398
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3448
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3465
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3453
    P
    clamav-0.101.3-1.19 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94590
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2960
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94577
    P
    gstreamer-plugins-good-1.20.1-150400.1.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95197
    P
    kernel-default-extra-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95028
    P
    kernel-docs-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94909
    P
    gnome-shell-search-provider-nautilus-41.2-150400.1.8 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95078
    P
    reiserfs-kmp-default-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95083
    P
    kernel-azure-5.14.21-150400.12.1 on GA media (Moderate)
    2022-06-22
    oval:com.redhat.rhsa:def:20221988
    P
    RHSA-2022:1988: kernel security, bug fix, and enhancement update (Important)
    2022-05-10
    oval:org.opensuse.security:def:101622
    P
    Security update for giflib (Moderate) (in QA)
    2022-04-15
    oval:org.opensuse.security:def:4570
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP5) (Important)
    2022-04-13
    oval:org.opensuse.security:def:4500
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:102065
    P
    Security update for ffmpeg (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:102060
    P
    Security update for java-11-openjdk (Important)
    2021-09-03
    oval:org.opensuse.security:def:102292
    P
    Security update for haproxy (Important)
    2021-08-18
    oval:org.opensuse.security:def:6452
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:117881
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:108958
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:73676
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:5804
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:68250
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:118629
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:109533
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:102867
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:108288
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:95579
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:118029
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:109106
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:64554
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:102440
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:96177
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:119793
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:109653
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:102987
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:117470
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:75961
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:10653
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:95727
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:7161
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:70793
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:67541
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:74657
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:96315
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:66893
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:117802
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:108731
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:42110
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:65589
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:107956
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:101290
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:8367
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:101909
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:99666
    P
    (Important)
    2021-08-14
    oval:org.opensuse.security:def:76289
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:101482
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:65659
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:8389
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:6476
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:102291
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:67221
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:99980
    P
    (Important)
    2021-08-14
    oval:org.opensuse.security:def:73863
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:1119
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:68347
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:101797
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:1733
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:102327
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:100316
    P
    (Important)
    2021-08-14
    oval:org.opensuse.security:def:64741
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:111664
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:1214
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:101874
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:99403
    P
    (Important)
    2021-08-14
    oval:org.opensuse.security:def:10690
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:1775
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:7258
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:70830
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:67565
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:100645
    P
    (Important)
    2021-08-14
    oval:org.opensuse.security:def:74727
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:1256
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:95960
    P
    Security update for the Linux Kernel (Important)
    2021-08-12
    oval:org.opensuse.security:def:68797
    P
    Security update for the Linux Kernel (Important)
    2021-08-12
    oval:org.opensuse.security:def:42109
    P
    Security update for the Linux Kernel (Important)
    2021-08-12
    oval:org.opensuse.security:def:118430
    P
    Security update for the Linux Kernel (Important)
    2021-08-12
    oval:org.opensuse.security:def:109339
    P
    Security update for the Linux Kernel (Important)
    2021-08-12
    oval:org.opensuse.security:def:102673
    P
    Security update for the Linux Kernel (Important)
    2021-08-12
    oval:org.opensuse.security:def:68674
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:67215
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:111007
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:75956
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:1547
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:111658
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:66888
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:108726
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:118368
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:109282
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:102616
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:68660
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:76283
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:95903
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:5799
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    BACK
    linux linux kernel 5.4.66
    linux linux kernel 5.4.54
    ibm spectrum protect plus 10.1.0