Information disclosure in Linux kernel - CVE-2021-3773

 

Information disclosure in Linux kernel - CVE-2021-3773

Published: June 2, 2022 / Updated: July 19, 2024


Vulnerability identifier: #VU63920
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3773
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in the netfilter. A remote attacker can infer openvpn connection endpoint informationand gain unauthorized access to sensitive information on the system.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Anolis OS
Fedora
Migration Toolkit for Containers
Red Hat Advanced Cluster Management for Kubernetes
kernel-doc
kernel-abi-stablelists
python3-perf
perf
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
kernel-headers
kernel-devel
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
kernel
bpftool
kernel (Red Hat package)
kernel-rt (Red Hat package)

How to mitigate CVE-2021-3773

Install updates from vendor's website.

Linux kernel - update to 5.14.0-49.el9
Migration Toolkit for Containers - addressed in versions 1.6.5, 1.7.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.11, 2.4.5, 2.5.0
kernel-doc - update to 4.18.0-372.9.1
kernel-abi-stablelists - update to 4.18.0-372.9.1
python3-perf - update to 4.18.0-372.9.1
perf - update to 4.18.0-372.9.1
kernel-tools-libs - update to 4.18.0-372.9.1
kernel-tools - update to 4.18.0-372.9.1
kernel-modules-extra - update to 4.18.0-372.9.1
kernel-modules - update to 4.18.0-372.9.1
kernel-headers - update to 4.18.0-372.9.1
kernel-devel - update to 4.18.0-372.9.1
kernel-debug-modules-extra - update to 4.18.0-372.9.1
kernel-debug-modules - update to 4.18.0-372.9.1
kernel-debug-devel - update to 4.18.0-372.9.1
kernel-debug-core - update to 4.18.0-372.9.1
kernel-debug - update to 4.18.0-372.9.1
kernel-cross-headers - update to 4.18.0-372.9.1
kernel-core - update to 4.18.0-372.9.1
kernel - update to 4.18.0-372.9.1
bpftool - update to 4.18.0-372.9.1
kernel (Red Hat package) - update to 4.18.0-372.9.1.el8
kernel-rt (Red Hat package) - update to 4.18.0-372.9.1.rt7.166.el8
kernel - addressed in versions 5.15.15-100.fc34, 5.15.15-200.fc35

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins