PT-2021-6923 · Linux+9 · Linux Kernel+9
Published
2021-04-20
·
Updated
2024-03-24
·
CVE-2021-42739
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 5.14.13
Description
The issue is related to a buffer overflow in the firewire subsystem of the Linux kernel, specifically in the drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c files. This overflow is caused by the mishandling of bounds checking by the avc ca pmt function. The vulnerability can be exploited by a local user on the host machine, potentially allowing them to crash the system or escalate privileges, thus affecting the confidentiality, integrity, and availability of the system.
Recommendations
For Linux kernel versions through 5.14.13, consider updating to a version that contains a fix for this issue to prevent potential exploitation. As a temporary workaround, restricting access to the firewire subsystem or the specific drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c files may help minimize the risk of exploitation. However, the most effective resolution is to apply the official patch or update once available.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu