CVE-2021-46992 is a vulnerability in the Linux kernel's nftables netfilter component, specifically affecting the nft_hash_buckets() function. It stems from integer overflows when handling the number of hash buckets, which are stored in 32-bit variables. This flaw can lead to a shift-out-of-bounds error, as demonstrated by syzbot, potentially causing a denial of service or information disclosure. Rated with a CVSS score of 7.1 (HIGH), the vulnerability has a local attack vector (AV:L) and low attack complexity (AC:L), requiring low privileges (PR:L). While it does not impact integrity (I:N), it poses a high risk to confidentiality (C:H) and availability (A:H). The vulnerability is classified under CWE-125 (Out-of-bounds Read). Currently, there is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.9, < 4.14.233CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.191CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.120CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.38CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.11.22CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.