PT-2021-3581 · Selinux+6 · Selinux+6

Published

2021-02-19

·

Updated

2025-11-03

·

CVE-2021-36085

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions SELinux version 3.2
Description The issue is related to a use-after-free in the cil verify classperms() function of the SELinux access control system. This can potentially allow an attacker to cause a denial of service. The cil verify classperms() function is called from verify map perm classperms and hashtab map.
Recommendations For SELinux version 3.2, consider disabling the cil verify classperms() function as a temporary workaround until a patch is available. Restrict access to the affected components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2021:4513
BDU:2021-03683
CESA-2021_4513
CVE-2021-36085
DLA-3930-1
OPENSUSE-SU-2024:10990-1
RHSA-2021:4513
RHSA-2021_4513
RLSA-2021:4513
USN-5391-1

Affected Products

Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Selinux
Ubuntu