← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-3612

An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
EPSS Probability:0.69%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-20 ↗CWE-20->CWE-119

Affected Products & Versions

Vendor Product Affected Versions
linux linux_kernel all
redhat enterprise_linux 7.0, 8.0
fedoraproject fedora 34
debian debian_linux 9.0
oracle communications_cloud_native_core_binding_support_function 22.1.3
oracle communications_cloud_native_core_network_exposure_function 22.1.1
oracle communications_cloud_native_core_policy 22.2.0
netapp cloud_backup all
netapp solidfire_baseboard_management_controller_firmware all
netapp solidfire_baseboard_management_controller all
netapp h300s_firmware all
netapp h300s all
netapp h500s_firmware all
netapp h500s all
netapp h700s_firmware all
netapp h700s all
netapp h300e_firmware all
netapp h300e all
netapp h500e_firmware all
netapp h500e all
netapp h700e_firmware all
netapp h700e all
netapp h410s_firmware all
netapp h410s all
netapp h410c_firmware all
netapp h410c all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.693%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2021-06-21T00:00:00
Published2021-07-09T10:33:16
Last Updated2024-08-03T17:01:07

LINK COPIED TO CLIPBOARD