Review reviewHigh

CVE-2021-46955

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with KASAN, it's possible to see the following splat while testing fragmentation of IPv4 packets: BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60 Read of size 1 at addr ffff888112fc713c by task handler2/1367 CPU: 0 PID: 1367 Comm: handler2 Not tainted 5.12.0-rc6+ #418 Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014 Call Trace: dump_stack+0x92/0xc1 print_address_description.con...

CVSS
7.1
EPSS
0.74%
51.1% percentile
CISA KEV
Not listed
Published
2024.02.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.74%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with KASAN, it's possible to see the following splat while testing fragmentation of IPv4 packets: BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60 Read of size 1 at addr ffff888112fc713c by task handler2/1367 CPU: 0 PID: 1367 Comm: handler2 Not tainted 5.12.0-rc6+ #418 Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014 Call Trace: dump_stack+0x92/0xc1 print_address_description.con...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 119bbaa6795a4f4aed46994cc7d9ab01989c87e3 < b1d7280f9ba1bfdbc3af5bdb82e51f014854f26f, >= d543907a4730400f5c5b684c57cb5bbbfd6136ab < 23e17ec1a5eb53fe39cc34fa5592686d5acd0dac, >= 8387fbac8e18e26a60559adc63e0b7067303b0a4 < 5a52fa8ad45b5a593ed416adf326538638454ff1, >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < df9e900de24637be41879e2c50afb713ec4e8b2e, >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < 490ad0a2390442d0a7b8c00972a83dbb09cab142, >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < a1478374b0bda89b4277a8afd39208271faad4be, >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < d841d3cf5297fde4ce6a41ff35451d0e82917f3e, >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < b3502b04e84ac5349be95fc033c17bd701d2787a, >= d52e5a7e7ca49457dd31fc8b42fb7c0d58a31221 < 7c0ea5930c1c211931819d83cfb157bff1539a4c, >= df9ece1148e2ec242871623dedb004f7a1387125, >= 4.4.134 < 4.4.269, >= 4.9.104 < 4.9.269, >= 4.14.45 < 4.14.233, >= 3.16.57 < 3.17, >= 4.16, >= 4.16 < 4.19.191, >= 4.20 < 5.4.118, >= 5.5 < 5.10.36, >= 5.11 < 5.11.20, >= 5.12 < 5.12.3
Fixed versions
4.4.269, 4.9.269, 4.14.233, 4.19.191, 5.4.118, 5.10.36, 5.11.20, 5.12.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125