PT-2021-8081 · Linux+7 · Linux Kernel+7

Published

2021-12-31

·

Updated

2024-08-20

·

CVE-2021-46934

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.19.223 Linux kernel versions prior to 5.4.169 Linux kernel versions prior to 5.10.89 Linux kernel versions prior to 5.15 Linux kernel versions prior to 5.15.12
Description The issue is related to the i2c transfer() function in the Linux kernel's i2c component, which does not properly validate user data. This can cause warnings when incorrect user data is provided, such as zero messages. To prevent this, validation checks have been added for user data in compact ioctl. The vulnerability may allow an attacker to impact the integrity of protected information.
Recommendations For Linux kernel versions prior to 4.19.223, update to version 4.19.223 or later. For Linux kernel versions prior to 5.4.169, update to version 5.4.169 or later. For Linux kernel versions prior to 5.10.89, update to version 5.10.89 or later. For Linux kernel versions prior to 5.15, update to version 5.15 or later. For Linux kernel versions prior to 5.15.12, update to version 5.15.12 or later. As a temporary workaround, consider restricting access to the i2c transfer() function until a patch is available.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:3618
ALSA-2024:3627
BDU:2024-06346
CESA-2024_3618
CESA-2024_3627
CVE-2021-46934
INFSA-2024_3618
INFSA-2024_3627
OESA-2024-1392
OESA-2024-1393
OPENSUSE-SU-2024_0857-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
RHSA-2024:3618
RHSA-2024:3627
RHSA-2024_3618
RHSA-2024_3627
RLSA-2024:3618
RLSA-2024:3627
SUSE-SU-2024:0855-1
SUSE-SU-2024:0856-1
SUSE-SU-2024:0857-1
SUSE-SU-2024:0900-1
SUSE-SU-2024:0900-2
SUSE-SU-2024:0926-1
SUSE-SU-2024:0977-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse