{"id":"CVE-2021-3501","title":"A flaw was found in the Linux kernel in versions before 5.12","summary":"A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The hig…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-787"],"vendor":"redhat","product":"virtualization","affected":["linux_kernel < 5.12","enterprise_linux = 8.0","enterprise_linux_for_real_time = 8","enterprise_linux_for_real_time_for_nfv = 8","enterprise_linux_for_real_time_for_nfv_tus = 8.4","enterprise_linux_for_real_time_tus = 8.4","fedora = 33","virtualization = 4.0","virtualization_host = 4.0","cloud_backup","solidfire_baseboard_management_controller_firmware","h300s_firmware","h500s_firmware","h700s_firmware","h300e_firmware","h500e_firmware","h700e_firmware","h410s_firmware","h410c_firmware"],"patched":["linux_kernel 5.12"],"published":"2021-05-06","updated":"2026-08-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-3501","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1950136","label":"secalert@redhat.com"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c4f2ee3f68c9a4bf1653d15f1a9a435ae33f7a","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20210618-0008/","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1950136","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c4f2ee3f68c9a4bf1653d15f1a9a435ae33f7a","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210618-0008/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00374,"epssPercentile":0.31185,"ingestedAt":"2026-08-05T22:52:53.164Z","slug":"CVE-2021-3501","body":"## Overview\n\nA flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.\n\n## Affected\n\n- `linux_kernel < 5.12`\n- `enterprise_linux = 8.0`\n- `enterprise_linux_for_real_time = 8`\n- `enterprise_linux_for_real_time_for_nfv = 8`\n- `enterprise_linux_for_real_time_for_nfv_tus = 8.4`\n- `enterprise_linux_for_real_time_tus = 8.4`\n- `fedora = 33`\n- `virtualization = 4.0`\n- `virtualization_host = 4.0`\n- `cloud_backup`\n- `solidfire_baseboard_management_controller_firmware`\n- `h300s_firmware`\n- `h500s_firmware`\n- `h700s_firmware`\n- `h300e_firmware`\n- `h500e_firmware`\n- `h700e_firmware`\n- `h410s_firmware`\n- `h410c_firmware`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.12`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}