PT-2021-4237 · Linux+4 · Linux Kernel+4

Billy Jheng Bing-Jhong

+1

·

Published

2021-05-05

·

Updated

2024-06-15

·

CVE-2021-3491

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.13-rc1 Linux kernel versions 5.7-rc1 through 5.12.3 Linux kernel versions 5.11 through 5.11.20 Linux kernel versions 5.10 through 5.10.36
Description The issue is related to a buffer overflow in the io uring subsystem of the Linux kernel, allowing an attacker to execute arbitrary code. This is due to the MAX RW COUNT limit being bypassed in the PROVIDE BUFFERS operation, leading to negative values being used in mem rw when reading /proc//mem, which could result in a heap overflow.
Recommendations For Linux kernel versions prior to 5.7-rc1, there is no information about a fix. For Linux kernel versions 5.7-rc1 through 5.12.3, update to version 5.12.4 or later. For Linux kernel versions 5.11 through 5.11.20, update to version 5.11.21 or later. For Linux kernel versions 5.10 through 5.10.36, update to version 5.10.37 or later. As a temporary workaround, consider restricting access to the io uring subsystem until a patch is available.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1805
ALT-PU-2021-1833
ALT-PU-2021-1855
ALT-PU-2021-1888
ALT-PU-2021-1896
ALT-PU-2021-1912
ALT-PU-2021-1920
ALT-PU-2021-1961
ALT-PU-2021-1985
ALT-PU-2021-1990
ALT-PU-2021-2293
ALT-PU-2021-2305
ALT-PU-2021-2307
ALT-PU-2021-2370
ALT-PU-2021-2672
ALT-PU-2021-2677
ALT-PU-2021-2678
ALT-PU-2021-3481
ALT-PU-2022-1240
BDU:2021-04843
CVE-2021-3491
MGASA-2021-0214
MGASA-2021-0215
OPENSUSE-SU-2021:0843-1
OPENSUSE-SU-2021:0947-1
OPENSUSE-SU-2021:1975-1
OPENSUSE-SU-2021:1977-1
OPENSUSE-SU-2021_0843-1
OPENSUSE-SU-2021_0947-1
OPENSUSE-SU-2021_1975-1
OPENSUSE-SU-2021_1977-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
SUSE-SU-2021:1887-1
SUSE-SU-2021:1888-1
SUSE-SU-2021:1889-1
SUSE-SU-2021:1890-1
SUSE-SU-2021:1891-1
SUSE-SU-2021:1899-1
SUSE-SU-2021:1912-1
SUSE-SU-2021:1913-1
SUSE-SU-2021:1975-1
SUSE-SU-2021:1977-1
SUSE-SU-2021:2208-1
SUSE-SU-2021:2421-1
USN-4948-1
USN-4949-1
USN-4950-1
ZDI-21-589

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu