Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Haoran Luo

#47923of 56,330
5.5Total CVSS
Vulnerabilities · 1
PT-2021-4148
5.5
2021-07-20
Linux · Linux Kernel · CVE-2021-3679
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 5.14-rc3 **Description** A lack of CPU resource in the Linux kernel tracing module functionality was found in the way a user uses the trace ring buffer in a specific way. Only privileged local users, with CAP SYS ADMIN capability, could use this flaw to starve the resources, causing a denial of service. **Recommendations** For versions prior to 5.14-rc3, update to version 5.14-rc3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the trace ring buffer functionality to minimize the risk of exploitation. Additionally, limiting the capabilities of local users to prevent them from obtaining the CAP SYS ADMIN capability can also help mitigate the risk.