CVE-2021-20269

A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1934261 Issue Tracking Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:kexec-tools_project:kexec-tools:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:kexec-tools_project:kexec-tools:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:-:*:*:*:*:*:*:*

Information

Published : 2022-03-10 09:41

Updated : 2023-02-12 14:15


NVD link : CVE-2021-20269

Mitre link : CVE-2021-20269


JSON object : View

CWE
CWE-276

Incorrect Default Permissions

Advertisement

dedicated server usa

Products Affected

redhat

  • enterprise_linux

kexec-tools_project

  • kexec-tools

fedoraproject

  • fedora