CVE-2021-47336

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/05/2024
Last modified:
12/05/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> smackfs: restrict bytes count in smk_set_cipso()<br /> <br /> Oops, I failed to update subject line.<br /> <br /> From 07571157c91b98ce1a4aa70967531e64b78e8346 Mon Sep 17 00:00:00 2001<br /> Date: Mon, 12 Apr 2021 22:25:06 +0900<br /> Subject: [PATCH] smackfs: restrict bytes count in smk_set_cipso()<br /> <br /> Commit 7ef4c19d245f3dc2 ("smackfs: restrict bytes count in smackfs write<br /> functions") missed that count &gt; SMK_CIPSOMAX check applies to only<br /> format == SMK_FIXED24_FMT case.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.9.276 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.10 (including) 4.14.240 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15 (including) 4.19.198 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.133 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.51 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.12.18 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.13 (including) 5.13.3 (excluding)