PT-2024-1443 · Openeuler+7 · Openeuler Kernel+7

Solar Designer

·

Published

2023-05-09

·

Updated

2025-04-02

·

CVE-2021-33631

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openEuler kernel versions 4.19.90 through 4.19.90-2401.3 openEuler kernel versions 5.10.0-60.18.0 through 5.10.0-183.0.0
Description The issue is related to an integer overflow in the ext4 write inline data end() function of the openEuler kernel on Linux, specifically in the filesystem modules. This allows for a forced integer overflow, which can impact the confidentiality, integrity, and availability of protected information.
Recommendations For openEuler kernel versions 4.19.90 through 4.19.90-2401.3, update to version 4.19.90-2401.3 or later. For openEuler kernel versions 5.10.0-60.18.0 through 5.10.0-183.0.0, update to version 5.10.0-183.0.0 or later. As a temporary workaround, consider restricting access to the vulnerable filesystem modules until a patch is available.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:1607
BDU:2024-00928
CESA-2024_1607
CESA-2024_1614
CVE-2021-33631
OESA-2024-1030
OESA-2024-1031
OESA-2024-1032
OESA-2024-1033
OESA-2024-1034
OESA-2024-1035
OPENSUSE-SU-2024_0469-1
OPENSUSE-SU-2024_0515-1
RHSA-2023:2148
RHSA-2023:2458
RHSA-2023_2148
RHSA-2023_2458
RHSA-2024:1607
RHSA-2024:1614
RHSA-2024:1653
RHSA-2024:1836
RHSA-2024:1840
RHSA-2024:2621
RHSA-2024_1607
RHSA-2024_1614
RLSA-2024:1607
RLSA-2024:1614
RXSA-2024:1607
SUSE-SU-2024:0463-1
SUSE-SU-2024:0468-1
SUSE-SU-2024:0469-1
SUSE-SU-2024:0474-1
SUSE-SU-2024:0476-1
SUSE-SU-2024:0478-1
SUSE-SU-2024:0483-1
SUSE-SU-2024:0484-1
SUSE-SU-2024:0514-1
SUSE-SU-2024:0515-1
SUSE-SU-2024:0516-1
USN-6865-1
USN-6866-1
USN-6866-2
USN-6866-3

Affected Products

Almalinux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Openeuler Kernel