cbcvebase.
CVE-2021-37600
published 2021-07-30

CVE-2021-37600: An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianutil-linux< util-linux 2.36.1-8 (bookworm)util-linux 2.36.1-8 (bookworm)
kernelutil-linux<= 2.37.1
kernelutil-linux>= 0 < 2.36.1-82.36.1-8
kernelutil-linux>= 0 < 2.36.1-82.36.1-8
kernelutil-linux>= 0 < 2.36.1-82.36.1-8
kernelutil-linux>= 0 < 2.36.1-82.36.1-8
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_util-linux_2.32.1-5_on_cbl_mariner_1.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM