CVE-2021-47474
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
22/05/2024
Last modified:
24/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
comedi: vmk80xx: fix bulk-buffer overflow<br />
<br />
The driver is using endpoint-sized buffers but must not assume that the<br />
tx and rx buffers are of equal size or a malicious device could overflow<br />
the slab-allocated receive buffer when doing bulk transfers.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.31 (including) | 4.4.292 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.5 (including) | 4.9.290 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.10 (including) | 4.14.255 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15 (including) | 4.19.217 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.20 (including) | 5.4.159 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.79 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.14.18 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.15 (including) | 5.15.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/063f576c43d589a4c153554b681d32b3f8317c7b
- https://git.kernel.org/stable/c/0866dcaa828c21bc2f94dac00e086078f11b5772
- https://git.kernel.org/stable/c/1ae4715121a57bc6fa29fd992127b01907f2f993
- https://git.kernel.org/stable/c/47b4636ebdbeba2044b3db937c4d2b6a4fe3d0f2
- https://git.kernel.org/stable/c/78cdfd62bd54af615fba9e3ca1ba35de39d3871d
- https://git.kernel.org/stable/c/7b0e356189327287d0eb98ec081bd6dd97068cd3
- https://git.kernel.org/stable/c/7cfb35db607760698d299fd1cf7402dfa8f09973
- https://git.kernel.org/stable/c/b7fd7f3387f070215e6be341e68eb5c087eeecc0
- https://git.kernel.org/stable/c/e0e6a63fd97ad95fe05dfd77268a1952551e11a7
- https://git.kernel.org/stable/c/063f576c43d589a4c153554b681d32b3f8317c7b
- https://git.kernel.org/stable/c/0866dcaa828c21bc2f94dac00e086078f11b5772
- https://git.kernel.org/stable/c/1ae4715121a57bc6fa29fd992127b01907f2f993
- https://git.kernel.org/stable/c/47b4636ebdbeba2044b3db937c4d2b6a4fe3d0f2
- https://git.kernel.org/stable/c/78cdfd62bd54af615fba9e3ca1ba35de39d3871d
- https://git.kernel.org/stable/c/7b0e356189327287d0eb98ec081bd6dd97068cd3
- https://git.kernel.org/stable/c/7cfb35db607760698d299fd1cf7402dfa8f09973
- https://git.kernel.org/stable/c/b7fd7f3387f070215e6be341e68eb5c087eeecc0
- https://git.kernel.org/stable/c/e0e6a63fd97ad95fe05dfd77268a1952551e11a7



