CVE-2021-20269

A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1934261 Issue Tracking Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1934261 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:kexec-tools_project:kexec-tools:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:kexec-tools_project:kexec-tools:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:46

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=1934261 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1934261 - Issue Tracking, Third Party Advisory

Information

Published : 2022-03-10 17:41

Updated : 2024-11-21 05:46


NVD link : CVE-2021-20269

Mitre link : CVE-2021-20269

CVE.ORG link : CVE-2021-20269


JSON object : View

Products Affected

kexec-tools_project

  • kexec-tools

fedoraproject

  • fedora

redhat

  • enterprise_linux
CWE
CWE-276

Incorrect Default Permissions