CVE-2021-20265

MEDIUM

Linux Kernel < 7.7.1 - Memory Leak

Title source: rule

Description

A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 12.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-401 CWE-400
Status published

Affected Products (2)

linux/linux_kernel
oracle/tekelec_platform_distribution < 7.7.1

Timeline

Published Mar 10, 2021
Tracked Since Feb 18, 2026