OESA-2021-1318

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1318
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1318.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1318
Upstream
Published
2021-08-20T11:04:33Z
Modified
2026-08-18T01:15:46Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
kernel security update
Details

The Linux Kernel, the operating system core itself.

Security Fix(es):

A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causing denial of service.(CVE-2021-3679)

drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.(CVE-2021-38204)

drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).(CVE-2021-38205)

net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, and NF_SYSCTL_CT_BUCKETS sysctls.(CVE-2021-38209)

fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.(CVE-2021-38199)

drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.(CVE-2021-38207)

net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call.(CVE-2021-38208)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.19.90-2108.5.0.0103.oe1

Ecosystem specific

{
    "aarch64": [
        "kernel-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "kernel-debugsource-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "perf-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "kernel-source-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "python2-perf-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "python3-perf-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "kernel-tools-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "kernel-debuginfo-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "kernel-devel-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "perf-debuginfo-4.19.90-2108.5.0.0103.oe1.aarch64.rpm",
        "bpftool-4.19.90-2108.5.0.0103.oe1.aarch64.rpm"
    ],
    "src": [
        "kernel-4.19.90-2108.5.0.0103.oe1.src.rpm"
    ],
    "x86_64": [
        "kernel-source-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "python3-perf-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "kernel-tools-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "perf-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "perf-debuginfo-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "python2-perf-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "bpftool-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "kernel-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "kernel-debugsource-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "kernel-devel-4.19.90-2108.5.0.0103.oe1.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2108.5.0.0103.oe1.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2021-1318.json"

openEuler:20.03-LTS-SP2 / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.19.90-2108.5.0.0104.oe1

Ecosystem specific

{
    "aarch64": [
        "kernel-source-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "kernel-debugsource-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "perf-debuginfo-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "kernel-debuginfo-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "perf-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "kernel-devel-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "python2-perf-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "kernel-tools-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "kernel-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "python3-perf-4.19.90-2108.5.0.0104.oe1.aarch64.rpm",
        "bpftool-4.19.90-2108.5.0.0104.oe1.aarch64.rpm"
    ],
    "src": [
        "kernel-4.19.90-2108.5.0.0104.oe1.src.rpm"
    ],
    "x86_64": [
        "python3-perf-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "perf-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "kernel-devel-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "kernel-tools-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "kernel-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "python2-perf-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "kernel-source-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "kernel-debugsource-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "perf-debuginfo-4.19.90-2108.5.0.0104.oe1.x86_64.rpm",
        "bpftool-4.19.90-2108.5.0.0104.oe1.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2021-1318.json"