← Back to browse · API

CVE-2021-3501

Severity
HIGH
CVSS
7.1
Published
2021-05-06
Modified
2026-08-05
First seen
2026-08-06
Aliases
-
Products
fedoraproject:fedora, linux:linux_kernel, netapp:cloud_backup, netapp:h300e, netapp:h300e_firmware, netapp:h300s, netapp:h300s_firmware, netapp:h410c, netapp:h410c_firmware, netapp:h410s, netapp:h410s_firmware, netapp:h500e, netapp:h500e_firmware, netapp:h500s, netapp:h500s_firmware, netapp:h700e, netapp:h700e_firmware, netapp:h700s, netapp:h700s_firmware, netapp:solidfire_baseboard_management_controller_firmware, redhat:enterprise_linux, redhat:enterprise_linux_for_real_time, redhat:enterprise_linux_for_real_time_for_nfv, redhat:enterprise_linux_for_real_time_for_nfv_tus, redhat:enterprise_linux_for_real_time_tus, redhat:virtualization, redhat:virtualization_host
Sources
nvd CVE-2021-3501

Description

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.

References