PT-2021-3737 · Unknown+2 · Util-Linux+2
Kihong Heo
·
Published
2021-07-28
·
Updated
2024-08-04
·
CVE-2021-37600
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
util-linux versions through 2.37.1
Description
The issue is related to an integer overflow in the util-linux package, specifically in the ipcutils.c file. This overflow can potentially cause a buffer overflow if an attacker is able to manipulate system resources in a way that leads to a large number in the /proc/sysvipc/sem file. However, it is noted that this issue is unexploitable in GNU C Library environments and possibly in all realistic environments.
Recommendations
For util-linux versions through 2.37.1, update to a version later than 2.37.1 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific issue.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Util-Linux