Vulnerability Name:

CVE-2021-45095 (CCN-215548)

Assigned:2021-12-10
Published:2021-12-10
Updated:2022-04-06
Summary:pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-45095

Source: XF
Type: UNKNOWN
linux-kernel-cve202145095-info-disc(215548)

Source: CCN
Type: Linux Kernel GIT Repository
phonet: refcount leak in pep_sock_accep

Source: MISC
Type: Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=bcd0f93353326954817a4f9fa55ec57fb38acbb0

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/torvalds/linux/commit/bcd0f93353326954817a4f9fa55ec57fb38acbb0

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20220309 [SECURITY] [DLA 2940-1] linux security update

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20220309 [SECURITY] [DLA 2941-1] linux-4.19 security update

Source: DEBIAN
Type: Third Party Advisory
DSA-5050

Source: DEBIAN
Type: Third Party Advisory
DSA-5096

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version <= 5.15.8)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:11.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8029
    P
    kernel-docs-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7539
    P
    kernel-64kb-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8090
    P
    reiserfs-kmp-default-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3453
    P
    clamav-0.101.3-1.19 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3567
    P
    libXtst6-1.2.2-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3398
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3448
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95028
    P
    kernel-docs-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2960
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95078
    P
    reiserfs-kmp-default-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95083
    P
    kernel-azure-5.14.21-150400.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94590
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95197
    P
    kernel-default-extra-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:6183
    P
    Security update for the Linux Kernel (Important)
    2022-04-07
    oval:org.opensuse.security:def:5361
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:4306
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:4702
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:6184
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:6361
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:4740
    P
    Security update for the Linux RT Kernel (Critical)
    2022-02-22
    oval:org.opensuse.security:def:102157
    P
    Security update for the Linux RT Kernel (Critical)
    2022-02-21
    oval:org.opensuse.security:def:1600
    P
    Security update for the Linux RT Kernel (Critical)
    2022-02-21
    oval:org.opensuse.security:def:118440
    P
    Security update for the Linux RT Kernel (Critical)
    2022-02-21
    oval:org.opensuse.security:def:42343
    P
    Security update for the Linux RT Kernel (Critical)
    2022-02-21
    oval:org.opensuse.security:def:42199
    P
    Security update for the Linux RT Kernel (Critical)
    2022-02-21
    oval:org.opensuse.security:def:1812
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:125394
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:938
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:101851
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:99210
    P
    (Critical)
    2022-02-11
    oval:org.opensuse.security:def:100414
    P
    (Critical)
    2022-02-11
    oval:org.opensuse.security:def:42337
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:125797
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:1189
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:101894
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:99484
    P
    (Critical)
    2022-02-11
    oval:org.opensuse.security:def:102310
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:100748
    P
    (Critical)
    2022-02-11
    oval:org.opensuse.security:def:126960
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:1241
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:101998
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:99746
    P
    (Critical)
    2022-02-11
    oval:org.opensuse.security:def:1758
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:125120
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:102356
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:101630
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:127358
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:1418
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:100076
    P
    (Critical)
    2022-02-11
    oval:org.opensuse.security:def:118805
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:1563
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:119483
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:118239
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:118995
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:119668
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:119102
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:42193
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:118659
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:119300
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    oval:org.opensuse.security:def:102124
    P
    Security update for the Linux Kernel (Critical)
    2022-02-10
    BACK
    linux linux kernel *
    debian debian linux 9.0
    debian debian linux 10.0
    debian debian linux 11.0