CVE-2021-37600

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
30/07/2021
Last modified:
04/08/2024

Description

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:* 2.37.1 (including)
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*