Uninitialized Memory Information Disclosure Vulnerability
CVE-2021-34999

3.8LOW

Key Information:

Vendor
OpenBSD
Status
Vendor
CVE Published:
7 May 2024

Summary

The OpenBSD Kernel contains a vulnerability in its multicast routing implementation, leading to the potential disclosure of sensitive information. This issue arises from uninitialized memory being accessed, which can be exploited by local attackers with low-privileged code execution rights. By leveraging this flaw in conjunction with other vulnerabilities, it may be possible for attackers to escalate their privileges and execute arbitrary code within the kernel context, posing significant security risks to the integrity of the system.

Affected Version(s)

Kernel OpenBSD 6.9

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.