#VU92060 Buffer overflow in Linux kernel


Published: 2024-06-13

Vulnerability identifier: #VU92060

Vulnerability risk: Low

CVSSv3.1: 7.7 [AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-47548

CWE-ID: CWE-119

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to memory corruption within the hns_dsaf_ge_srst_by_port() function in drivers/net/ethernet/hisilicon/hns/hns_dsaf_misc.c. A local user can escalate privileges on the system.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/948968f8747650447c8f21c9fdba0e1973be040b
http://git.kernel.org/stable/c/abbd5faa0748d0aa95d5191d56ff7a17a6275bd1
http://git.kernel.org/stable/c/dd07f8971b81ad98cc754b179b331b57f35aa1ff
http://git.kernel.org/stable/c/99bb25cb6753beaf2c2bc37927c2ecc0ceff3f6d
http://git.kernel.org/stable/c/22519eff7df2d88adcc2568d86046ce1e2b52803
http://git.kernel.org/stable/c/fc7ffa7f10b9454a86369405d9814bf141b30627
http://git.kernel.org/stable/c/a66998e0fbf213d47d02813b9679426129d0d114


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability