PT-2024-1443 · Openeuler+7 · Openeuler Kernel+7
Solar Designer
·
Published
2023-05-09
·
Updated
2025-04-02
·
CVE-2021-33631
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openEuler kernel versions 4.19.90 through 4.19.90-2401.3
openEuler kernel versions 5.10.0-60.18.0 through 5.10.0-183.0.0
Description
The issue is related to an integer overflow in the
ext4 write inline data end() function of the openEuler kernel on Linux, specifically in the filesystem modules. This allows for a forced integer overflow, which can impact the confidentiality, integrity, and availability of protected information.Recommendations
For openEuler kernel versions 4.19.90 through 4.19.90-2401.3, update to version 4.19.90-2401.3 or later.
For openEuler kernel versions 5.10.0-60.18.0 through 5.10.0-183.0.0, update to version 5.10.0-183.0.0 or later.
As a temporary workaround, consider restricting access to the vulnerable filesystem modules until a patch is available.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Openeuler Kernel