Wind River Support Network

HomeDefectsLIN1023-232
Not to be fixed

LIN1023-232 : Security Advisory - linux - CVE-2021-3714

Created: Apr 26, 2023    Updated: Nov 7, 2023
Resolved Date: Nov 7, 2023
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.

https://nvd.nist.gov/vuln/detail/CVE-2021-3714
Live chat
Online