PT-2021-8145 · Linux+3 · Linux Kernel+3
Dmitry Osipenko
+1
·
Published
2021-12-12
·
Updated
2025-02-03
·
CVE-2021-47098
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to an integer overflow/underflow in hysteresis calculations in the Linux kernel's hwmon component, specifically in the lm90 module. This occurs when setting the hysteresis value to MAX LONG and the critical temperature limit is negative. The problem was addressed by using the clamp val() function to prevent overflow or underflow when setting the hysteresis temperature.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Red Os
Suse