- New CVE entry this week
Re: New CVE entry this week
toggle quoted messageShow quoted text
From: cip-dev@... [mailto:cip-dev@...] On Behalf Of Masami Ichikawa
Sent: Thursday, September 30, 2021 9:12 AM
To: cip-dev <cip-dev@...>
Subject: [cip-dev] New CVE entry this week
It's this week's CVE report.
This week reported one new CVE.
* New CVEs
CVE-2021-20317: lib/timerqueue: Rely on rbtree semantics for next timer
This bug has been fixed in 5.4-rc1 so that before 5.4 kernels are
affected. For 4.19, patch can be applied without any modification. For
4.4, it needs to modify patch to apply it.
According to the description in
it describes "This flaw allows a local attacker with special user
privileges to cause a denial of service" so I think this vulnerability
severity may be low.
CVSS v3 score is not provided.
This commit can be applied directly to 4.14 and 4.19.
However, other LTSs need to be other commit or fixes.
I attached a patch for 4.14 and 4.19.
Join email@example.com to automatically receive all group messages.