PT-2021-3737 · Unknown+2 · Util-Linux+2

Kihong Heo

·

Published

2021-07-28

·

Updated

2024-08-04

·

CVE-2021-37600

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions util-linux versions through 2.37.1
Description The issue is related to an integer overflow in the util-linux package, specifically in the ipcutils.c file. This overflow can potentially cause a buffer overflow if an attacker is able to manipulate system resources in a way that leads to a large number in the /proc/sysvipc/sem file. However, it is noted that this issue is unexploitable in GNU C Library environments and possibly in all realistic environments.
Recommendations For util-linux versions through 2.37.1, update to a version later than 2.37.1 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific issue.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2657
ALT-PU-2022-3036
BDU:2021-03990
CVE-2021-37600
DLA-3782-1
MGASA-2022-0076
OESA-2021-1308
OPENSUSE-SU-2021:1440-1
OPENSUSE-SU-2021:3474-1
OPENSUSE-SU-2021_1440-1
OPENSUSE-SU-2021_3474-1
SUSE-SU-2021:3463-1
SUSE-SU-2021:3474-1
SUSE-SU-2021:3475-1
SUSE-SU-2021:3523-1
SUSE-SU-2021_3463-1
SUSE-SU-2021_3474-1
SUSE-SU-2021_3475-1
SUSE-SU-2021_3523-1
SUSE-SU-2022:1103-1
SUSE-SU-2022:1105-1
SUSE-SU-2022:1108-1
SUSE-SU-2022_1103-1
SUSE-SU-2022_1105-1
SUSE-SU-2022_1108-1

Affected Products

Alt Linux
Suse
Util-Linux