Vulnerability Intelligence Report
CVE-2021-33909
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
EPSS Probability:9.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | all |
| fedoraproject | fedora | 34 |
| debian | debian_linux | 9.0, 10.0 |
| netapp | hci_management_node | all |
| netapp | solidfire | all |
| oracle | communications_session_border_controller | 8.2, 8.3, 8.4, 9.0 |
| sonicwall | sma1000_firmware | all |
| sonicwall | sma1000 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
9.808%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2021-06-07T00:00:00 |
| Published | 2021-07-20T18:01:34 |
| Last Updated | 2024-08-04T00:05:52 |
Community Chatter & Buzz