PT-2021-3597 · Selinux+6 · Selinux+6

Nicolas Iooss

·

Published

2021-01-18

·

Updated

2025-11-03

·

CVE-2021-36084

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions SELinux version 3.2
Description The issue is related to a use-after-free error in the cil verify classperms() function of the SELinux access control system. This error can be exploited to cause a denial of service. The cil verify classperms() function is called from cil verify classpermission and cil pre verify helper.
Recommendations For SELinux version 3.2, consider disabling the cil verify classperms() function as a temporary workaround until a patch is available. Restrict access to the affected components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2021:4513
BDU:2021-03701
CESA-2021_4513
CVE-2021-36084
DLA-3930-1
RHSA-2021:4513
RHSA-2021_4513
RLSA-2021:4513
USN-5391-1

Affected Products

Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Selinux
Ubuntu