← Back to browse · API

CVE-2021-38166

Severity
HIGH
CVSS
7.8
Published
2021-08-07
Modified
2026-08-05
First seen
2026-08-06
Aliases
-
Products
debian:debian_linux, fedoraproject:fedora, linux:linux_kernel
Sources
nvd CVE-2021-38166

Description

In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.

References