CVE-2021-47243
published 2024-05-21CVE-2021-47243: In the Linux kernel, the following vulnerability has been resolved: sch_cake: Fix out of bounds when parsing TCP options and header The TCP option parser in…
PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
sch_cake: Fix out of bounds when parsing TCP options and header
The TCP option parser in cake qdisc (cake_get_tcpopt and
cake_tcph_may_drop) could read one byte out of bounds. When the length
is 1, the execution flow gets into the loop, reads one byte of the
opcode, and if the opcode is neither TCPOPT_EOL nor TCPOPT_NOP, it reads
one more byte, which exceeds the length of 1.
This fix is inspired by commit 9609dad263f8 ("ipv4: tcp_input: fix stack
out of bounds when parsing TCP options.").
v2 changes:
Added doff validation in cake_get_tcphdr to avoid parsing garbage as TCP
header. Although it wasn't strictly an out-of-bounds access (memory was
allocated), garbage values could be read where CAKE expected the TCP
header if doff was smaller than 5.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.46-1 (bookworm) | linux 5.10.46-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 8b7138814f29933898ecd31dfc83e35a30ee69f5 < 595897ef118d6fe66690c4fc5b572028c9da95b7 | 595897ef118d6fe66690c4fc5b572028c9da95b7 |
| linux | linux | >= 8b7138814f29933898ecd31dfc83e35a30ee69f5 < 4cefa061fc63f4d2dff5ab4083f43857cd7a2335 | 4cefa061fc63f4d2dff5ab4083f43857cd7a2335 |
| linux | linux | >= 8b7138814f29933898ecd31dfc83e35a30ee69f5 < 3b491dd593d582ceeb27aa617600712a6bd14246 | 3b491dd593d582ceeb27aa617600712a6bd14246 |
| linux | linux | >= 8b7138814f29933898ecd31dfc83e35a30ee69f5 < 3371392c60e2685af30bd4547badd880f5df2b3f | 3371392c60e2685af30bd4547badd880f5df2b3f |
| linux | linux | >= 8b7138814f29933898ecd31dfc83e35a30ee69f5 < ba91c49dedbde758ba0b72f57ac90b06ddf8e548 | ba91c49dedbde758ba0b72f57ac90b06ddf8e548 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 4.19 < 4.19.196 | 4.19.196 |
| linux | linux_kernel | >= 4.20 < 5.4.128 | 5.4.128 |
| linux | linux_kernel | >= 5.11 < 5.12.13 | 5.12.13 |
| linux | linux_kernel | >= 5.5 < 5.10.46 | 5.10.46 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6pvp-xcj5-pgh8: In the Linux kernel, the following vulnerability has been resolved:
sch_cake: Fix out of bounds when parsing TCP options and header
The TCP option p
ghsa_unreviewed·2024-05-21
CVE-2021-47243 [HIGH] CWE-125 GHSA-6pvp-xcj5-pgh8: In the Linux kernel, the following vulnerability has been resolved:
sch_cake: Fix out of bounds when parsing TCP options and header
The TCP option p
In the Linux kernel, the following vulnerability has been resolved:
sch_cake: Fix out of bounds when parsing TCP options and header
The TCP option parser in cake qdisc (cake_get_tcpopt and
cake_tcph_may_drop) could read one byte out of bounds. When the length
is 1, the execution flow gets into the loop, reads one byte of the
opcode, and if the opcode is neither TCPOPT_EOL nor TCPOPT_NOP, it reads
one more byte, which exceeds the length of 1.
This fix is inspired by commit 9609dad263f8 ("ipv4: tcp_input: fix stack
out of bounds when parsing TCP options.").
v2 changes:
Added doff validation in cake_get_tcphdr to avoid parsing garbage as TCP
header. Although it wasn't strictly an out-of-bounds access (memory was
allocated), garbage values could be read where CAKE expected the TCP
header
OSV
CVE-2021-47243: In the Linux kernel, the following vulnerability has been resolved: sch_cake: Fix out of bounds when parsing TCP options and header The TCP option par
osv·2024-05-21·CVSS 7.1
CVE-2021-47243 [HIGH] CVE-2021-47243: In the Linux kernel, the following vulnerability has been resolved: sch_cake: Fix out of bounds when parsing TCP options and header The TCP option par
In the Linux kernel, the following vulnerability has been resolved: sch_cake: Fix out of bounds when parsing TCP options and header The TCP option parser in cake qdisc (cake_get_tcpopt and cake_tcph_may_drop) could read one byte out of bounds. When the length is 1, the execution flow gets into the loop, reads one byte of the opcode, and if the opcode is neither TCPOPT_EOL nor TCPOPT_NOP, it reads one more byte, which exceeds the length of 1. This fix is inspired by commit 9609dad263f8 ("ipv4: tcp_input: fix stack out of bounds when parsing TCP options."). v2 changes: Added doff validation in cake_get_tcphdr to avoid parsing garbage as TCP header. Although it wasn't strictly an out-of-bounds access (memory was allocated), garbage values could be read where CAKE expected the TCP header if do
Red Hat
kernel: sch_cake: Fix out of bounds when parsing TCP options and header
vendor_redhat·2024-05-21·CVSS 7.1
CVE-2021-47243 [HIGH] CWE-125 kernel: sch_cake: Fix out of bounds when parsing TCP options and header
kernel: sch_cake: Fix out of bounds when parsing TCP options and header
In the Linux kernel, the following vulnerability has been resolved:
sch_cake: Fix out of bounds when parsing TCP options and header
The TCP option parser in cake qdisc (cake_get_tcpopt and
cake_tcph_may_drop) could read one byte out of bounds. When the length
is 1, the execution flow gets into the loop, reads one byte of the
opcode, and if the opcode is neither TCPOPT_EOL nor TCPOPT_NOP, it reads
one more byte, which exceeds the length of 1.
This fix is inspired by commit 9609dad263f8 ("ipv4: tcp_input: fix stack
out of bounds when parsing TCP options.").
v2 changes:
Added doff validation in cake_get_tcphdr to avoid parsing garbage as TCP
header. Although it wasn't strictly an out-of-bounds access (memory was
allocate
Debian
CVE-2021-47243: linux - In the Linux kernel, the following vulnerability has been resolved: sch_cake: F...
vendor_debian·2021·CVSS 7.1
CVE-2021-47243 [HIGH] CVE-2021-47243: linux - In the Linux kernel, the following vulnerability has been resolved: sch_cake: F...
In the Linux kernel, the following vulnerability has been resolved: sch_cake: Fix out of bounds when parsing TCP options and header The TCP option parser in cake qdisc (cake_get_tcpopt and cake_tcph_may_drop) could read one byte out of bounds. When the length is 1, the execution flow gets into the loop, reads one byte of the opcode, and if the opcode is neither TCPOPT_EOL nor TCPOPT_NOP, it reads one more byte, which exceeds the length of 1. This fix is inspired by commit 9609dad263f8 ("ipv4: tcp_input: fix stack out of bounds when parsing TCP options."). v2 changes: Added doff validation in cake_get_tcphdr to avoid parsing garbage as TCP header. Although it wasn't strictly an out-of-bounds access (memory was allocated), garbage values could be read where CAKE expected the TCP header if do
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3371392c60e2685af30bd4547badd880f5df2b3fhttps://git.kernel.org/stable/c/3b491dd593d582ceeb27aa617600712a6bd14246https://git.kernel.org/stable/c/4cefa061fc63f4d2dff5ab4083f43857cd7a2335https://git.kernel.org/stable/c/595897ef118d6fe66690c4fc5b572028c9da95b7https://git.kernel.org/stable/c/ba91c49dedbde758ba0b72f57ac90b06ddf8e548https://git.kernel.org/stable/c/3371392c60e2685af30bd4547badd880f5df2b3fhttps://git.kernel.org/stable/c/3b491dd593d582ceeb27aa617600712a6bd14246https://git.kernel.org/stable/c/4cefa061fc63f4d2dff5ab4083f43857cd7a2335https://git.kernel.org/stable/c/595897ef118d6fe66690c4fc5b572028c9da95b7https://git.kernel.org/stable/c/ba91c49dedbde758ba0b72f57ac90b06ddf8e548
2024-05-21
Published