Input validation error in Intel Ethernet Controllers X722 series Linux drivers and Intel Ethernet Controllers 800 series Linux drivers - CVE-2021-0084

 

Input validation error in Intel Ethernet Controllers X722 series Linux drivers and Intel Ethernet Controllers 800 series Linux drivers - CVE-2021-0084

Published: August 12, 2021


Vulnerability identifier: #VU55814
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0084
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input. A local user can pass specially crafted input to the application and gain elevated privileges on the target system.


Affected software

Intel Ethernet Controllers X722 series Linux drivers
Intel Ethernet Controllers 800 series Linux drivers

How to mitigate CVE-2021-0084

Install updates from vendor's website.

Intel Ethernet Controllers X722 series Linux drivers - update to 1.3.19
Intel Ethernet Controllers 800 series Linux drivers - update to 1.3.19

External References

Related Security Bulletins