CVE-2021-3923: Infoleak
A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdmacm device node. While this access is unlikely to leak sensitive user information, it can be further used to defeat existing kernel protection mechanisms.
Other sources
A flaw was found in the linux kernels implementation of RDMA over infiniband. An attacker with a priviledged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdmacm device node.
While this access is unlikely to leak sensitive user information, it can be further used to defeat existing kernel protection mechanisms.
— Red Hat
Linux Kernel could allow a local authenticated attacker to obtain sensitive information, caused by a flaw in the implementation of RDMA over infiniband. By issuing commands to the /dev/infiniband/rdmacm device node, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3923?
CVE-2021-3923 has been classified as a medium severity vulnerability affecting the Linux kernel.
How do I fix CVE-2021-3923?
To fix CVE-2021-3923, update your Linux kernel to version 5.16 or later.
Who is affected by CVE-2021-3923?
CVE-2021-3923 affects users running versions of the Linux kernel up to 5.15.14, as well as certain versions of Red Hat Enterprise Linux.
What type of attack can CVE-2021-3923 facilitate?
CVE-2021-3923 can allow an attacker with a privileged local account to leak kernel stack information.
Is sensitive user information at risk with CVE-2021-3923?
While CVE-2021-3923 can leak kernel stack information, it is unlikely to expose sensitive user information.