CVE-2021-33656Out-of-bounds Write in Kernel

CWE-787Out-of-bounds Write24 documents7 sources
Severity
6.8MEDIUMNVD
OSV6.7OSV5.5
EPSS
0.0%
top 91.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateSep 30

Description

When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel< 5.10.127
Debianlinux/linux_kernel< 5.10.127-1+3
Ubuntulinux/linux_kernel< 5.4.0-125.141+1
debiandebian/linux< linux 5.14.6-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

10
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-09-30
OSV
linux-azure-fde vulnerabilities2022-09-09
OSV
linux-raspi-5.4 vulnerabilities2022-09-08
OSV
linux-hwe-5.4 vulnerabilities2022-09-05
OSV
linux-aws-5.4, linux-azure-5.4 vulnerabilities2022-09-02

📋Vendor Advisories

13
Ubuntu
Linux kernel vulnerabilities2022-09-30
Ubuntu
Linux kernel (Azure CVM) vulnerabilities2022-09-09
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2022-09-08
Ubuntu
Linux kernel (HWE) vulnerabilities2022-09-05
Ubuntu
Linux kernel (Oracle) vulnerability2022-09-05