imPC@ndo IT

Tracker / CVE-2021-33909

CVE-2021-33909

High 7.8

fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.

Affected products and versions

debian debian_linux
fedoraproject fedora
linux linux_kernel · 3.12.43 → 3.13
linux linux_kernel · 3.16 → 4.4.276
linux linux_kernel · 4.10 → 4.14.240
linux linux_kernel · 4.15 → 4.19.198
linux linux_kernel · 4.20 → 5.4.134
linux linux_kernel · 4.5 → 4.9.276
linux linux_kernel · 5.11 → 5.12.19
linux linux_kernel · 5.13 → 5.13.4
linux linux_kernel · 5.5 → 5.10.52
netapp hci_management_node
netapp solidfire
oracle communications_session_border_controller
sonicwall sma1000_firmware · … → 12.4.2-02044

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References