Out-of-bounds read in Linux kernel - CVE-2021-20177
Published: May 26, 2021 / Updated: June 2, 2021
Linux kernel
Linux Foundation
Description
The vulnerability allows a local privileged user to perform a denial of service (DoS) attack.
A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is affected.