CVE-2021-3501High· 7.1▾ TwilightA flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The hig…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
linux_kernel < 5.12enterprise_linux = 8.0enterprise_linux_for_real_time = 8enterprise_linux_for_real_time_for_nfv = 8enterprise_linux_for_real_time_for_nfv_tus = 8.4enterprise_linux_for_real_time_tus = 8.4fedora = 33virtualization = 4.0virtualization_host = 4.0cloud_backupsolidfire_baseboard_management_controller_firmwareh300s_firmwareh500s_firmwareh700s_firmwareh300e_firmwareh500e_firmwareh700e_firmwareh410s_firmwareh410c_firmwareUpgrade past the affected range:
linux_kernel 5.12Connected by shared product, vendor, weakness, or advisory.
CVE-2022-27666High· 7.8A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c
CVE-2025-7519Medium· 6.7A flaw was found in polkit
CVE-2022-0995High· 7.8An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem
CVE-2021-4090High· 7.1An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel
CVE-2020-1054High· 7.0An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory
CVE-2021-4034High· 7.8A local privilege escalation vulnerability was found on polkit's pkexec utility