← Back to browse · API

CVE-2021-45485

Severity
HIGH
CVSS
7.5
Published
2021-12-25
Modified
2026-08-05
First seen
2026-08-06
Aliases
-
Products
linux:linux_kernel, netapp:aff_a400, netapp:aff_a400_firmware, netapp:all_flash_fabric-attached_storage_8300, netapp:all_flash_fabric-attached_storage_8300_firmware, netapp:all_flash_fabric-attached_storage_8700, netapp:all_flash_fabric-attached_storage_8700_firmware, netapp:brocade_fabric_operating_system_firmware, netapp:e-series_santricity_os_controller, netapp:fabric-attached_storage_8300, netapp:fabric-attached_storage_8300_firmware, netapp:fabric-attached_storage_8700, netapp:fabric-attached_storage_8700_firmware, netapp:fabric-attached_storage_a400, netapp:fabric-attached_storage_a400_firmware, netapp:h300e, netapp:h300e_firmware, netapp:h300s, netapp:h300s_firmware, netapp:h410c, netapp:h410c_firmware, netapp:h410s, netapp:h410s_firmware, netapp:h500e, netapp:h500e_firmware, netapp:h500s, netapp:h500s_firmware, netapp:h610c, netapp:h610c_firmware, netapp:h610s, netapp:h610s_firmware, netapp:h615c, netapp:h615c_firmware, netapp:h700e, netapp:h700e_firmware, netapp:h700s, netapp:h700s_firmware, netapp:hci_compute_node, netapp:hci_compute_node_firmware, netapp:solidfire\,_enterprise_sds_\&_hci_storage_node, netapp:solidfire_\&_hci_management_node, oracle:communications_cloud_native_core_binding_support_function, oracle:communications_cloud_native_core_network_exposure_function, oracle:communications_cloud_native_core_policy
Sources
nvd CVE-2021-45485

Description

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.

References