VendorsCanonicalubuntu_linux21.10
Vulnerabilities

Canonical Ubuntu Linux 21.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

40CVEs
CVE-2022-0543
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
Published 2022-02-18 · Analyzed
10.0KEVEPSS 0.994
CVE-2021-45079
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
Published 2022-01-31 · Modified
9.1EPSS 0.028
CVE-2021-44142
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Published 2022-02-21 · Modified
9.0EPSS 0.734
CVE-2020-25719
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.
Published 2022-02-18 · Modified
9.0EPSS 0.017
CVE-2020-25722
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.
Published 2022-02-18 · Modified
8.8EPSS 0.016
CVE-2021-4093
A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or ins) using the exit reason SVM_EXIT_IOIO. This issue results in a crash of the entire system or a potential guest-to-host escape scenario.
Published 2022-02-18 · Modified
8.8EPSS 0.004
CVE-2021-44730
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
8.8EPSS 0.004
CVE-2022-1055
Use after Free in tc_new_tfilter allowing for privilege escalation in Linux Kernel
Published 2022-03-29 · Analyzed
8.6EPSS 0.005
CVE-2020-25717
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
Published 2022-02-18 · Modified
8.5EPSS 0.016
CVE-2021-4120
snapd could be made to bypass intended access restrictions through snap content interfaces and layout paths
Published 2022-02-17 · Modified
8.2EPSS 0.004
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Published 2022-01-28 · Analyzed
7.8KEV1 PoCEPSS 0.943
CVE-2021-44731
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
7.8EPSS 0.010
CVE-2021-45417
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
Published 2022-01-20 · Modified
7.8EPSS 0.005
CVE-2021-3899
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
Published 2024-06-03 · Analyzed
7.8EPSS 0.004
CVE-2021-3939
Free of static data in accountsservice
Published 2021-11-17 · Modified
7.8EPSS 0.004
CVE-2022-1242
Apport can be tricked into connecting to arbitrary sockets as the root user
Published 2024-06-03 · Analyzed
7.8EPSS 0.002
CVE-2022-28657
Apport does not disable python crash handler before entering chroot
Published 2024-06-04 · Modified
7.8EPSS 0.002
CVE-2021-44420
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
Published 2021-12-07 · Modified
7.5EPSS 0.023
CVE-2021-3905
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
Published 2022-08-23 · Modified
7.5EPSS 0.020
CVE-2021-3748
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.
Published 2022-03-23 · Modified
7.5EPSS 0.005
CVE-2021-32553
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32547
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32550
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32551
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32552
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32554
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32548
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32555
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32549
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2022-28655
is_closing_session() allows users to create arbitrary tcp dbus connections
Published 2024-06-04 · Modified
7.1EPSS 0.002
CVE-2021-3640
A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.
Published 2022-03-03 · Modified
7.0EPSS 0.004
CVE-2021-3975
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
Published 2022-08-23 · Modified
6.5EPSS 0.015
CVE-2016-2124
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
Published 2022-02-18 · Modified
5.9EPSS 0.018
CVE-2021-4115
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
Published 2022-02-21 · Modified
5.5EPSS 0.005
CVE-2021-3155
snapd created ~/snap with too-wide permissions
Published 2022-02-17 · Modified
5.5EPSS 0.003
CVE-2022-28654
is_closing_session() allows users to fill up apport.log
Published 2024-06-04 · Modified
5.5EPSS 0.003
CVE-2022-2084
sensitive data exposure in cloud-init logs
Published 2023-04-19 · Modified
5.5EPSS 0.002
CVE-2022-28658
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
Published 2024-06-04 · Modified
5.5EPSS 0.002
CVE-2022-28652
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
Published 2024-06-04 · Modified
5.5EPSS 0.002
CVE-2022-28656
is_closing_session() allows users to consume RAM in the Apport process
Published 2024-06-04 · Modified
5.5EPSS 0.002