CVE-2021-33631
published 2024-01-18CVE-2021-33631: Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.37%
29.4th percentile
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 4.4.0-256.290 | 4.4.0-256.290 |
| linux | linux_kernel | >= 0 < 4.15.0-226.238 | 4.15.0-226.238 |
| openatom | openeuler | >= 4.19.90 < 4.19.90-2401.3 | 4.19.90-2401.3 |
| openatom | openeuler | >= 5.10.0-60.18.0 < 5.10.0-183.0.0 | 5.10.0-183.0.0 |
| openeuler | kernel | >= 4.19.90 < 4.19.90-2401.3 | 4.19.90-2401.3 |
| openeuler | kernel | >= 5.10.0-60.18.0 < 5.10.0-183.0.0 | 5.10.0-183.0.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-azure vulnerabilities
osv·2024-07-10·CVSS 7.8
CVE-2021-33631 [HIGH] linux-azure vulnerabilities
linux-azure vulnerabilities
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly validate data state on write operations. An
attacker could use this to construct a malicious ext4 file system image
that, when mounted, could cause a denial of service (system crash).
(CVE-2021-33631)
It was discovered that the ATA over Ethernet (AoE) driver in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. An attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2023-6270)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the initial Branch History
Injection vulnerability (CVE-2022-0001) were insufficient for I
OSV
linux-azure, linux-azure-4.15 vulnerabilities
osv·2024-07-04·CVSS 7.8
CVE-2021-33631 [HIGH] linux-azure, linux-azure-4.15 vulnerabilities
linux-azure, linux-azure-4.15 vulnerabilities
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly validate data state on write operations. An
attacker could use this to construct a malicious ext4 file system image
that, when mounted, could cause a denial of service (system crash).
(CVE-2021-33631)
It was discovered that the ATA over Ethernet (AoE) driver in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. An attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2023-6270)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the initial Branch History
Injection vulnerability (CVE-2022-0001) were
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
osv·2024-07-03·CVSS 7.8
CVE-2021-33631 [HIGH] linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly validate data state on write operations. An
attacker could use this to construct a malicious ext4 file system image
that, when mounted, could cause a denial of service (system crash).
(CVE-2021-33631)
It was discovered that the ATA over Ethernet (AoE) driver in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. An attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2023-6270)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the ini
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-07-03·CVSS 7.8
CVE-2021-33631 [HIGH] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly validate data state on write operations. An
attacker could use this to construct a malicious ext4 file system image
that, when mounted, could cause a denial of service (system crash).
(CVE-2021-33631)
It was discovered that the ATA over Ethernet (AoE) driver in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. An attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2023-6270)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the initial Branch History
Injection vulnerability (CVE-
OSV
CVE-2021-33631: Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow
osv·2024-01-18·CVSS 7.8
CVE-2021-33631 [HIGH] CVE-2021-33631: Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
GHSA
GHSA-ff22-5jp8-224r: Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow
ghsa_unreviewed·2024-01-18
CVE-2021-33631 [MEDIUM] CWE-190 GHSA-ff22-5jp8-224r: Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2024-07-10·CVSS 5.5
CVE-2024-26898 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly validate data state on write operations. An
attacker could use this to construct a malicious ext4 file system image
that, when mounted, could cause a denial of service (system crash).
(CVE-2021-33631)
It was discovered that the ATA over Ethernet (AoE) driver in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. An attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2023-6270)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the init
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2024-07-04·CVSS 5.5
CVE-2021-33631 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly validate data state on write operations. An
attacker could use this to construct a malicious ext4 file system image
that, when mounted, could cause a denial of service (system crash).
(CVE-2021-33631)
It was discovered that the ATA over Ethernet (AoE) driver in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. An attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2023-6270)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the init
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-07-03·CVSS 5.5
CVE-2021-33631 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly validate data state on write operations. An
attacker could use this to construct a malicious ext4 file system image
that, when mounted, could cause a denial of service (system crash).
(CVE-2021-33631)
It was discovered that the ATA over Ethernet (AoE) driver in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. An attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2023-6270)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the initial Bran
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-07-03·CVSS 5.5
CVE-2021-33631 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly validate data state on write operations. An
attacker could use this to construct a malicious ext4 file system image
that, when mounted, could cause a denial of service (system crash).
(CVE-2021-33631)
It was discovered that the ATA over Ethernet (AoE) driver in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. An attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2023-6270)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the initial Bran
Red Hat
kernel: ext4: kernel bug in ext4_write_inline_data_end()
vendor_redhat·2024-01-18·CVSS 5.5
CVE-2021-33631 [MEDIUM] CWE-190 kernel: ext4: kernel bug in ext4_write_inline_data_end()
kernel: ext4: kernel bug in ext4_write_inline_data_end()
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
A flaw was found in the openEuler kernel in Linux filesystem modules that allows an integer overflow via mounting a corrupted filesystem. This issue affects the openEuler kernel in versions from 4.19.90 through 4.19.90-2401.3 and 5.10.0-60.18.0 through 5.10.0-183.0.0.
Statement: Red Hat has protection mechanisms in place against buffer overflows, such as FORTIFY_SOURCE, Position Independent Executables or Stack Smashing Protection.
Mitigation: Mitigation for this issue is either not available
Debian
CVE-2021-33631: linux - Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (files...
vendor_debian·2021·CVSS 5.5
CVE-2021-33631 [MEDIUM] CVE-2021-33631: linux - Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (files...
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/01/30/10http://www.openwall.com/lists/oss-security/2024/01/30/3http://www.openwall.com/lists/oss-security/2024/01/30/4http://www.openwall.com/lists/oss-security/2024/01/30/5http://www.openwall.com/lists/oss-security/2024/01/30/9http://www.openwall.com/lists/oss-security/2024/01/31/2http://www.openwall.com/lists/oss-security/2024/01/31/3http://www.openwall.com/lists/oss-security/2024/02/02/6http://www.openwall.com/lists/oss-security/2024/02/02/9http://www.openwall.com/lists/oss-security/2024/02/03/1https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5c099c4fdc438014d5893629e70a8ba934433ee8https://gitee.com/src-openeuler/kernel/pulls/1389https://gitee.com/src-openeuler/kernel/pulls/1396https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1030https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1031https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1032https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1033https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1034https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1035http://www.openwall.com/lists/oss-security/2024/01/30/10http://www.openwall.com/lists/oss-security/2024/01/30/3http://www.openwall.com/lists/oss-security/2024/01/30/4http://www.openwall.com/lists/oss-security/2024/01/30/5http://www.openwall.com/lists/oss-security/2024/01/30/9http://www.openwall.com/lists/oss-security/2024/01/31/2http://www.openwall.com/lists/oss-security/2024/01/31/3http://www.openwall.com/lists/oss-security/2024/02/02/6http://www.openwall.com/lists/oss-security/2024/02/02/9http://www.openwall.com/lists/oss-security/2024/02/03/1https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5c099c4fdc438014d5893629e70a8ba934433ee8https://gitee.com/src-openeuler/kernel/pulls/1389https://gitee.com/src-openeuler/kernel/pulls/1396https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1030https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1031https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1032https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1033https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1034https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1035
2024-01-18
Published