PT-2021-8145 · Linux+3 · Linux Kernel+3

Dmitry Osipenko

+1

·

Published

2021-12-12

·

Updated

2025-02-03

·

CVE-2021-47098

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an integer overflow/underflow in hysteresis calculations in the Linux kernel's hwmon component, specifically in the lm90 module. This occurs when setting the hysteresis value to MAX LONG and the critical temperature limit is negative. The problem was addressed by using the clamp val() function to prevent overflow or underflow when setting the hysteresis temperature.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08417
CVE-2021-47098
INFSA-2024_9315
OPENSUSE-SU-2024_1321-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:1320-1
SUSE-SU-2024:1321-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1

Affected Products

Linux Kernel
Red Hat
Red Os
Suse