CVE-2021-0900
published 2021-12-17CVE-2021-0900: In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution…
PriorityP415medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.12%
1.9th percentile
In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672055.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-37g7-9m6f-rhqh: In apusys, there is a possible out of bounds read due to an incorrect bounds check
ghsa_unreviewed·2021-12-18
CVE-2021-0900 [MEDIUM] CWE-20 GHSA-37g7-9m6f-rhqh: In apusys, there is a possible out of bounds read due to an incorrect bounds check
In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672055.
Red Hat
kernel: smackfs: restrict bytes count in smk_set_cipso()
vendor_redhat·2024-05-21·CVSS 7.8
CVE-2021-47336 [HIGH] CWE-20 kernel: smackfs: restrict bytes count in smk_set_cipso()
kernel: smackfs: restrict bytes count in smk_set_cipso()
In the Linux kernel, the following vulnerability has been resolved:
smackfs: restrict bytes count in smk_set_cipso()
Oops, I failed to update subject line.
From 07571157c91b98ce1a4aa70967531e64b78e8346 Mon Sep 17 00:00:00 2001
Date: Mon, 12 Apr 2021 22:25:06 +0900
Subject: [PATCH] smackfs: restrict bytes count in smk_set_cipso()
Commit 7ef4c19d245f3dc2 ("smackfs: restrict bytes count in smackfs write
functions") missed that count > SMK_CIPSOMAX check applies to only
format == SMK_FIXED24_FMT case.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Ent
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-17
Published