#VU91304 Buffer overflow in Linux kernel


Published: 2024-06-08

Vulnerability identifier: #VU91304

Vulnerability risk: Low

CVSSv3.1: 7.7 [AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-47474

CWE-ID: CWE-119

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to memory corruption within the vmk80xx_do_bulk_msg() function in drivers/staging/comedi/drivers/vmk80xx.c. A local user can escalate privileges on the system.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/e0e6a63fd97ad95fe05dfd77268a1952551e11a7
http://git.kernel.org/stable/c/7cfb35db607760698d299fd1cf7402dfa8f09973
http://git.kernel.org/stable/c/0866dcaa828c21bc2f94dac00e086078f11b5772
http://git.kernel.org/stable/c/063f576c43d589a4c153554b681d32b3f8317c7b
http://git.kernel.org/stable/c/1ae4715121a57bc6fa29fd992127b01907f2f993
http://git.kernel.org/stable/c/b7fd7f3387f070215e6be341e68eb5c087eeecc0
http://git.kernel.org/stable/c/7b0e356189327287d0eb98ec081bd6dd97068cd3
http://git.kernel.org/stable/c/47b4636ebdbeba2044b3db937c4d2b6a4fe3d0f2
http://git.kernel.org/stable/c/78cdfd62bd54af615fba9e3ca1ba35de39d3871d


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability