CVE-2021-3753

MEDIUM

Linux Kernel - Info Disclosure

Title source: llm
STIX 2.1

Description

A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality.

References (4)

Core 4

Scores

CVSS v3 4.7
EPSS 0.0002
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125 CWE-362
Status published
Products (13)
linux/linux_kernel < 5.15
netapp/active_iq_unified_manager
netapp/bootstrap_os
netapp/element_software
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
netapp/hci_management_node
... and 3 more
Published Feb 16, 2022
Tracked Since Feb 18, 2026