CVE-2021-36086
published 2021-07-01CVE-2021-36086: The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.59%
44.4th percentile
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libsepol | < libsepol 3.3-1 (bookworm) | libsepol 3.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| selinux_project | selinux | < 3.3 | 3.3 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libsepol vulnerabilities
vendor_ubuntu·2022-04-27·CVSS 3.3
CVE-2021-36086 [LOW] libsepol vulnerabilities
Title: libsepol vulnerabilities
Summary: Several security issues were fixed in libsepol.
Nicolas Iooss discovered that libsepol incorrectly handled memory
when handling policies. An attacker could possibly use this issue
to cause a crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2021-36084)
It was discovered that libsepol incorrectly handled memory when
handling policies. An attacker could possibly use this issue to cause
a crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-36085)
It was discovered that libsepol incorrectly handled memory when
handling policies. An attacker could possibly use this issue to cause
a crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affects Ubu
Red Hat
libsepol: use-after-free in cil_reset_classpermission()
vendor_redhat·2021-04-19·CVSS 3.3
CVE-2021-36086 [LOW] CWE-416 libsepol: use-after-free in cil_reset_classpermission()
libsepol: use-after-free in cil_reset_classpermission()
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
Package: libsepol (Red Hat Enterprise Linux 6) - Not affected
Package: libsepol (Red Hat Enterprise Linux 7) - Fix deferred
Package: libsepol (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-36086: libsepol - The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermissio...
vendor_debian·2021·CVSS 3.3
CVE-2021-36086 [LOW] CVE-2021-36086: libsepol - The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermissio...
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
Scope: local
bookworm: resolved (fixed in 3.3-1)
bullseye: resolved (fixed in 3.1-1+deb11u1)
forky: resolved (fixed in 3.3-1)
sid: resolved (fixed in 3.3-1)
trixie: resolved (fixed in 3.3-1)
GHSA
GHSA-7qg9-9x35-j2qf: The CIL compiler in SELinux 3
ghsa_unreviewed·2022-05-24
CVE-2021-36086 [MEDIUM] CWE-416 GHSA-7qg9-9x35-j2qf: The CIL compiler in SELinux 3
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
OSV
libsepol vulnerabilities
osv·2022-04-27·CVSS 3.3
CVE-2021-36084 [LOW] libsepol vulnerabilities
libsepol vulnerabilities
Nicolas Iooss discovered that libsepol incorrectly handled memory
when handling policies. An attacker could possibly use this issue
to cause a crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2021-36084)
It was discovered that libsepol incorrectly handled memory when
handling policies. An attacker could possibly use this issue to cause
a crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-36085)
It was discovered that libsepol incorrectly handled memory when
handling policies. An attacker could possibly use this issue to cause
a crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affects Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2021-36086
OSV
CVE-2021-36086: The CIL compiler in SELinux 3
osv·2021-07-01·CVSS 3.3
CVE-2021-36086 [LOW] CVE-2021-36086: The CIL compiler in SELinux 3
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32177https://github.com/SELinuxProject/selinux/commit/c49a8ea09501ad66e799ea41b8154b6770fec2c8https://github.com/google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-536.yamlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32177https://github.com/SELinuxProject/selinux/commit/c49a8ea09501ad66e799ea41b8154b6770fec2c8https://github.com/google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-536.yamlhttps://lists.debian.org/debian-lts-announce/2024/10/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/https://security.netapp.com/advisory/ntap-20250207-0004/
2021-07-01
Published