Vulnerability Name:

CVE-2021-45485 (CCN-216133)

Assigned:2021-05-31
Published:2021-05-31
Updated:2023-02-24
Summary:In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-327
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-45485

Source: cve@mitre.org
Type: Technical Description, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Release Notes, Vendor Advisory
cve@mitre.org

Source: XF
Type: UNKNOWN
linux-kernel-cve202145485-info-disc(216133)

Source: CCN
Type: Linux Kernel GIT Repository
ipv6: use prandom_u32() for ID generation

Source: cve@mitre.org
Type: Patch, Vendor Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: CCN
Type: IBM Security Bulletin 6593539 (Spectrum Copy Data Management)
Vulnerabilities in the Linux Kernel affect IBM Spectrum Copy Data Management

Source: CCN
Type: IBM Security Bulletin 6596971 (Spectrum Protect Plus)
Multiple vulnerabilities in Linux Kernel affect IBM Spectrum Protect Plus

Source: CCN
Type: IBM Security Bulletin 6615959 (Elastic Storage System)
There are multiple vulnerabilities in the Linux Kernel used in IBM Elastic Storage System

Source: CCN
Type: IBM Security Bulletin 6840317 (Power HMC)
Vulnerability in Kernel (CVE-2021-45485) affects Power HMC

Source: CCN
Type: IBM Security Bulletin 6848577 (DataPower Gateway)
IBM DataPower Gateway vulnerable to network state information leakage (CVE-2021-20322, CVE-2021-45485, CVE-2021-45486)

Source: CCN
Type: IBM Security Bulletin 6851373 (MQ Appliance)
IBM MQ Appliance is affected by kernel vulnerabilities (CVE-2021-45485, CVE-2021-45486 and CVE-2022-1012)

Source: CCN
Type: IBM Security Bulletin 6858043 (Spectrum Virtualize)
Multiple vulnerabilities in the Linux kernel affect IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products

Source: cve@mitre.org
Type: Patch, Third Party Advisory
cve@mitre.org

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-45485

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::nfv:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:8::realtime:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:5.13:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:spectrum_protect_plus:10.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:hardware_management_console:9.2.950.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_copy_data_management:2.2.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_copy_data_management:2.2.15.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:datapower_gateway:10.5.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:elastic_storage_system:6.1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:datapower_gateway:10.5.0.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7593
    P
    libgstphotography-1_0-0-1.22.0-150500.1.3 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7720
    P
    mozilla-nspr-32bit-4.34.1-150000.3.26.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3743
    P
    perl-32bit-5.18.2-12.20.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:4601
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 12 SP5) (Important)
    2022-05-10
    oval:com.redhat.rhsa:def:20221975
    P
    RHSA-2022:1975: kernel-rt security and bug fix update (Important)
    2022-05-10
    oval:com.redhat.rhsa:def:20221988
    P
    RHSA-2022:1988: kernel security, bug fix, and enhancement update (Important)
    2022-05-10
    oval:org.opensuse.security:def:42191
    P
    Security update for the Linux Kernel (Important)
    2022-02-02
    oval:org.opensuse.security:def:118439
    P
    Security update for the Linux Kernel (Important)
    2022-02-02
    oval:org.opensuse.security:def:101844
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:42297
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:99205
    P
    (Important)
    2022-01-26
    oval:org.opensuse.security:def:102353
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:118646
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:101986
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:42189
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:99741
    P
    (Important)
    2022-01-26
    oval:org.opensuse.security:def:910
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:119415
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:100408
    P
    (Important)
    2022-01-26
    oval:org.opensuse.security:def:1751
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:1237
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:118730
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:101612
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:119600
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:102307
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:118182
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:101893
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:99479
    P
    (Important)
    2022-01-26
    oval:org.opensuse.security:def:118920
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:100070
    P
    (Important)
    2022-01-26
    oval:org.opensuse.security:def:1176
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:100742
    P
    (Important)
    2022-01-26
    oval:org.opensuse.security:def:1805
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:1375
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:119225
    P
    Security update for the Linux Kernel (Important)
    2022-01-26
    oval:org.opensuse.security:def:1560
    P
    Security update for the Linux Kernel (Important)
    2022-01-25
    oval:org.opensuse.security:def:102122
    P
    Security update for the Linux Kernel (Important)
    2022-01-25
    oval:org.opensuse.security:def:100400
    P
    (Important)
    2022-01-19
    oval:org.opensuse.security:def:1748
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:1232
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:101590
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:102306
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:101892
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:99472
    P
    (Important)
    2022-01-19
    oval:org.opensuse.security:def:100062
    P
    (Important)
    2022-01-19
    oval:org.opensuse.security:def:1159
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:100734
    P
    (Important)
    2022-01-19
    oval:org.opensuse.security:def:1799
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:1316
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:101837
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:42268
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:99198
    P
    (Important)
    2022-01-19
    oval:org.opensuse.security:def:102351
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:101969
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:99734
    P
    (Important)
    2022-01-19
    oval:org.opensuse.security:def:859
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:4742
    P
    Security update for the Linux Kernel (Important)
    2022-01-17
    oval:org.opensuse.security:def:21845
    P
    Security update for the Linux Kernel (Important)
    2022-01-17
    oval:org.opensuse.security:def:87575
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:33111
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:58934
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:42355
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:34682
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:60505
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:1602
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:68809
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:102159
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:6188
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:34681
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:60504
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:6359
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:5357
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:26227
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:4305
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:35294
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:19626
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:61117
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:6177
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:4701
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:20589
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:111873
    P
    Security update for the Linux Kernel (Important)
    2022-01-11
    oval:org.opensuse.security:def:1564
    P
    Security update for the Linux Kernel (Important)
    2022-01-11
    oval:org.opensuse.security:def:76456
    P
    Security update for the Linux Kernel (Important)
    2022-01-11
    oval:org.opensuse.security:def:68682
    P
    Security update for the Linux Kernel (Important)
    2022-01-11
    oval:org.opensuse.security:def:102125
    P
    Security update for the Linux Kernel (Important)
    2022-01-11
    oval:org.opensuse.security:def:6299
    P
    Security update for the Linux Kernel (Important)
    2022-01-11
    oval:org.opensuse.security:def:67388
    P
    Security update for the Linux Kernel (Important)
    2022-01-11
    oval:org.opensuse.security:def:74758
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:6491
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:111858
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:67580
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:8402
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:70850
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:65690
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:76445
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:7298
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:68387
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:10710
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:6288
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:67377
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:73954
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:64832
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    BACK
    linux linux kernel 5.13 -
    ibm spectrum protect plus 10.1.0
    ibm hardware management console 9.2.950.0
    ibm spectrum copy data management 2.2.0.0
    ibm spectrum copy data management 2.2.15.0
    ibm datapower gateway 10.5.0.0
    ibm elastic storage system 6.1.0.0
    ibm datapower gateway 10.5.0.2