CVE-2021-36086Use After Free in Project Selinux

CWE-416Use After Free7 documents6 sources
Severity
3.3LOWNVD
EPSS
0.0%
top 95.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateMay 24

Description

The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

debiandebian/libsepol< libsepol 3.3-1 (bookworm)

Also affects: Debian Linux 11.0, Fedora 35

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7qg9-9x35-j2qf: The CIL compiler in SELinux 32022-05-24
OSV
libsepol vulnerabilities2022-04-27
OSV
CVE-2021-36086: The CIL compiler in SELinux 32021-07-01

📋Vendor Advisories

3
Ubuntu
libsepol vulnerabilities2022-04-27
Red Hat
libsepol: use-after-free in cil_reset_classpermission()2021-04-19
Debian
CVE-2021-36086: libsepol - The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermissio...2021