
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was found in the fq_pie module of Linux Kernel impacting net/sched, where an out-of-bounds access during network traffic handling could lead to memory corruption. The vulnerability is tracked as CVE-2021-47175 and was discovered in the Flow Queue PIE packet scheduler implementation (Red Hat CVE).
The vulnerability exists in the fq_pie_qdisc_enqueue function where improper handling of flow selection could result in accessing memory beyond the allocated region. Specifically, the issue occurs when selecting 'q->flows + q->flows_cnt' as a valid flow, which points to an address beyond the allocated memory. The vulnerability has been assigned a CVSS v3 score of 7.1, indicating moderate severity (Red Hat CVE, Kernel Git).
The vulnerability could allow attackers to execute arbitrary code or cause a denial of service (DoS) condition through out-of-bounds memory access in the network traffic handling path (Red Hat CVE).
The vulnerability can be triggered through network traffic handling when using the fq_pie queueing discipline. A proof-of-concept exists using a specific sequence of traffic control (tc) commands that can trigger the out-of-bounds access (Kernel Git).
Red Hat recommends updating the affected packages as soon as possible, as no practical mitigation has been identified for this vulnerability. The fix involves modifying the fq_pie traffic path to prevent selection of invalid flow addresses (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."