PT-2021-6923 · Linux+9 · Linux Kernel+9

Published

2021-04-20

·

Updated

2024-03-24

·

CVE-2021-42739

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.14.13
Description The issue is related to a buffer overflow in the firewire subsystem of the Linux kernel, specifically in the drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c files. This overflow is caused by the mishandling of bounds checking by the avc ca pmt function. The vulnerability can be exploited by a local user on the host machine, potentially allowing them to crash the system or escalate privileges, thus affecting the confidentiality, integrity, and availability of the system.
Recommendations For Linux kernel versions through 5.14.13, consider updating to a version that contains a fix for this issue to prevent potential exploitation. As a temporary workaround, restricting access to the firewire subsystem or the specific drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c files may help minimize the risk of exploitation. However, the most effective resolution is to apply the official patch or update once available.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1988
ALT-PU-2021-3220
ALT-PU-2021-3232
ALT-PU-2021-3270
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-6601
BDU:2022-02682
CESA-2022_0063
CESA-2022_1975
CESA-2022_1988
CVE-2021-42739
DLA-2843-1
DLA-2941-1
DSA-5096-1
MGASA-2021-0507
MGASA-2021-0508
OESA-2021-1407
OPENSUSE-SU-2021:1477-1
OPENSUSE-SU-2021:3641-1
OPENSUSE-SU-2021:3675-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_1460-1
OPENSUSE-SU-2021_1477-1
OPENSUSE-SU-2021_3641-1
OPENSUSE-SU-2021_3655-1
OPENSUSE-SU-2021_3675-1
OPENSUSE-SU-2021_3876-1
RHSA-2022:0063
RHSA-2022:0065
RHSA-2022:1975
RHSA-2022:1988
RHSA-2022_0063
RHSA-2022_0065
RHSA-2022_1975
RHSA-2022_1988
RLSA-2022:1975
RLSA-2022:1988
SUSE-SU-2021:14849-1
SUSE-SU-2021:3640-1
SUSE-SU-2021:3641-1
SUSE-SU-2021:3642-1
SUSE-SU-2021:3658-1
SUSE-SU-2021:3675-1
SUSE-SU-2021:3723-1
SUSE-SU-2021:3748-1
SUSE-SU-2021:3754-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3929-1
SUSE-SU-2021:3935-1
SUSE-SU-2021:3972-1
SUSE-SU-2021_14849-1
SUSE-SU-2022:0234-1
SUSE-SU-2022:0237-1
SUSE-SU-2022:0238-1
SUSE-SU-2022:0241-1
SUSE-SU-2022:0242-1
SUSE-SU-2022:0243-1
SUSE-SU-2022:0246-1
SUSE-SU-2022:0254-1
SUSE-SU-2022:0255-1
SUSE-SU-2022:0257-1
SUSE-SU-2022:0263-1
SUSE-SU-2022:0267-1
SUSE-SU-2022:0270-1
SUSE-SU-2022:0291-1
SUSE-SU-2022:0292-1
SUSE-SU-2022:0293-1
SUSE-SU-2022:0295-1
SUSE-SU-2022:0296-1
SUSE-SU-2022:0298-1
SUSE-SU-2022:0325-1
SUSE-SU-2022:0327-1
SUSE-SU-2022:0328-1
USN-5165-1
USN-5207-1
USN-5265-1
USN-5266-1
USN-5267-1
USN-5267-2
USN-5267-3
USN-5268-1
USN-5361-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu