CVE-2021-3753: Race Condition
A race problem was seen in the vtkioctl in drivers/tty/vt/vtioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vcmode is not protected by lock-in vtioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality.
Other sources
Linux Kernel could allow a local attacker to obtain sensitive information, caused by an out-of-bounds read flaw in VT. By using a specially-crafted vcvisibleorigin setting, an attacker could exploit this vulnerability to obtain sensitive information, or cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3753?
The severity of CVE-2021-3753 is considered high due to its impact on data confidentiality.
How do I fix CVE-2021-3753?
To fix CVE-2021-3753, update your Linux kernel to version 5.15 or apply the recommended patches for versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
What systems are affected by CVE-2021-3753?
CVE-2021-3753 affects various versions of the Linux kernel, including specific Red Hat Enterprise Linux and Debian packages.
What type of vulnerability is CVE-2021-3753?
CVE-2021-3753 is a race condition vulnerability that can lead to out of bounds reading in the Linux kernel.
What are the potential consequences of CVE-2021-3753?
The consequences of CVE-2021-3753 include potential unauthorized access to sensitive data due to compromised data confidentiality.