CVE-2021-20261
Estado: ModificadaMedia (6.4)—
Se encontró una condición de carrera en la implementación del kernel de Linux del software manejador del controlador de la unidad de disquete. El impacto de este problema es reducido por el hecho de que los permisos predeterminados en el dispositivo de disquete (/dev/fd0) están restringidos para root. Si los permisos en el dispositivo han cambiado, el impacto cambia mucho. En la configuración predeterminada, son requeridos permisos de root (o equivalentes) para atacar este fallo
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-362
Referencias
- https://bugzilla.redhat.com/show_bug.cgi?id=1932150
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a0c80efe5956ccce9fe7ae5c78542578c07bc20a
- https://bugzilla.redhat.com/show_bug.cgi?id=1932150
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a0c80efe5956ccce9fe7ae5c78542578c07bc20a
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-20261",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.4,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.5
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "kernel",
"versions": [
{
"status": "affected",
"version": "kernel 5.12-rc2"
}
]
}
]
}
],
"published": "2021-03-11T21:15:11.983",
"references": [
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1932150",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a0c80efe5956ccce9fe7ae5c78542578c07bc20a",
"tags": [
"Mailing List",
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1932150",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a0c80efe5956ccce9fe7ae5c78542578c07bc20a",
"tags": [
"Mailing List",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the fact that the default permissions on the floppy device (/dev/fd0) are restricted to root. If the permissions on the device have changed the impact changes greatly. In the default configuration root (or equivalent) permissions are required to attack this flaw."
},
{
"lang": "es",
"value": "Se encontró una condición de carrera en la implementación del kernel de Linux del software manejador del controlador de la unidad de disquete. El impacto de este problema es reducido por el hecho de que los permisos predeterminados en el dispositivo de disquete (/dev/fd0) están restringidos para root. Si los permisos en el dispositivo han cambiado, el impacto cambia mucho. En la configuración predeterminada, son requeridos permisos de root (o equivalentes) para atacar este fallo"
}
],
"lastModified": "2026-06-17T03:33:33.773",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E422399C-2CB8-4293-9B4F-FD5703C1BA97",
"versionEndExcluding": "4.5"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.5:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28316352-6847-4D33-8E69-F3C933F42A04"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.5:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5011ED56-97F0-4754-9C98-B28B806DF6DD"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.5:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7FC0A28-90D9-4DF3-8A2A-49C3D4CB470A"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.5:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D90B29E-F7B6-4EAB-83D2-1C339310D34D"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.5:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02A2E198-C184-459C-9B7C-8A9C74A6DCEE"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}