A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
{ "binaries": [ { "binary_version": "5.10.0-1029.30", "binary_name": "linux-buildinfo-5.10.0-1029-oem" }, { "binary_version": "5.10.0-1029.30", "binary_name": "linux-headers-5.10.0-1029-oem" }, { "binary_version": "5.10.0-1029.30", "binary_name": "linux-image-unsigned-5.10.0-1029-oem" }, { "binary_version": "5.10.0-1029.30", "binary_name": "linux-image-unsigned-5.10.0-1029-oem-dbgsym" }, { "binary_version": "5.10.0-1029.30", "binary_name": "linux-modules-5.10.0-1029-oem" }, { "binary_version": "5.10.0-1029.30", "binary_name": "linux-oem-5.10-headers-5.10.0-1029" }, { "binary_version": "5.10.0-1029.30", "binary_name": "linux-oem-5.10-tools-5.10.0-1029" }, { "binary_version": "5.10.0-1029.30", "binary_name": "linux-oem-5.10-tools-host" }, { "binary_version": "5.10.0-1029.30", "binary_name": "linux-tools-5.10.0-1029-oem" } ], "availability": "No subscription required" }