PT-2021-3582 · Selinux+6 · Selinux+6

Published

2021-03-18

·

Updated

2025-11-03

·

CVE-2021-36086

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions SELinux version 3.2
Description The issue is related to a use-after-free in the cil reset classpermission() function of the CIL compiler in SELinux. This function is called from cil reset classperms set and cil reset classperms list. The exploitation of this issue may allow an attacker to cause a denial of service.
Recommendations For SELinux version 3.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the cil reset classpermission() function until a patch is available. Restrict access to the CIL compiler to minimize the risk of exploitation.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4513
BDU:2021-03684
CESA-2021_4513
CVE-2021-36086
DLA-3930-1
OESA-2022-1753
OPENSUSE-SU-2024:10990-1
RHSA-2021:4513
RHSA-2021_4513
RLSA-2021:4513
USN-5391-1

Affected Products

Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Selinux
Ubuntu