cbcvebase.
CVE-2021-46965
published 2024-02-27

CVE-2021-46965: In the Linux kernel, the following vulnerability has been resolved: mtd: physmap: physmap-bt1-rom: Fix unintentional stack access Cast &data to (char *) in…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mtd: physmap: physmap-bt1-rom: Fix unintentional stack access Cast &data to (char *) in order to avoid unintentionally accessing the stack. Notice that data is of type u32, so any increment to &data will be in the order of 4-byte chunks, and this piece of code is actually intended to be a byte offset. Addresses-Coverity-ID: 1497765 ("Out-of-bounds access")

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= b3e79e7682e075326df8041b826b03453acacd0a < 34ec706bf0b7c4ca249a729c1bcb91f706c7a7be34ec706bf0b7c4ca249a729c1bcb91f706c7a7be
linuxlinux>= b3e79e7682e075326df8041b826b03453acacd0a < 4e4ebb827bf09311469ffd9d0c14ed40ed9747aa4e4ebb827bf09311469ffd9d0c14ed40ed9747aa
linuxlinux>= b3e79e7682e075326df8041b826b03453acacd0a < 4d786870e3262ec098a3b4ed10b895176bc66ecb4d786870e3262ec098a3b4ed10b895176bc66ecb
linuxlinux>= b3e79e7682e075326df8041b826b03453acacd0a < 683313993dbe1651c7aa00bb42a041d70e914925683313993dbe1651c7aa00bb42a041d70e914925
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 5.10 < 5.10.365.10.36
linuxlinux_kernel>= 5.11 < 5.11.205.11.20
linuxlinux_kernel>= 5.12 < 5.12.35.12.3

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.