CVE-2021-47288
published 2024-05-21CVE-2021-47288: In the Linux kernel, the following vulnerability has been resolved: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf() Fix an 11-year old…
PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
Fix an 11-year old bug in ngene_command_config_free_buf() while
addressing the following warnings caught with -Warray-bounds:
arch/alpha/include/asm/string.h:22:16: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]
arch/x86/include/asm/string_32.h:182:25: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]
The problem is that the original code is trying to copy 6 bytes of
data into a one-byte size member _config_ of the wrong structue
FW_CONFIGURE_BUFFERS, in a single call to memcpy(). This causes a
legitimate compiler warning because memcpy() overruns the length
of &com.cmd.ConfigureBuffers.config. It seems that the right
structure is FW_CONFIGURE_FREE_BUFFERS, instead, because it contains
6 more members apart from the header _hdr_. Also, the name of
the function ngene_command_config_free_buf() suggests that the actual
intention is to ConfigureFreeBuffers, instead of ConfigureBuffers
(which takes place in the function ngene_command_config_buf(), above).
Fix this by enclosing those 6 members of struct FW_CONFIGURE_FREE_BUFFERS
into new struct config, and use &com.cmd.ConfigureFreeBuffers.config as
the destination address, instead of &com.cmd.ConfigureBuffers.config,
when calling memcpy().
This also helps with the ongoing efforts to globally enable
-Warray-bounds and get us closer to being able to tighten the
FORTIFY_SOURCE routines on memcpy().
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= dae52d009fc950b5c209260d50fcc000f5becd3c < 4487b968e5eacd02c493303dc2b61150bb7fe4b2 | 4487b968e5eacd02c493303dc2b61150bb7fe4b2 |
| linux | linux | >= dae52d009fc950b5c209260d50fcc000f5becd3c < c6ddeb63dd543b5474b0217c4e47538b7ffd7686 | c6ddeb63dd543b5474b0217c4e47538b7ffd7686 |
| linux | linux | >= dae52d009fc950b5c209260d50fcc000f5becd3c < e818f2ff648581a6c553ae2bebc5dcef9a8bb90c | e818f2ff648581a6c553ae2bebc5dcef9a8bb90c |
| linux | linux | >= dae52d009fc950b5c209260d50fcc000f5becd3c < ec731c6ef564ee6fc101fc5d73e3a3a953d09a00 | ec731c6ef564ee6fc101fc5d73e3a3a953d09a00 |
| linux | linux | >= dae52d009fc950b5c209260d50fcc000f5becd3c < e617fa62f6cf859a7b042cdd6c73af905ff8fca3 | e617fa62f6cf859a7b042cdd6c73af905ff8fca3 |
| linux | linux | >= dae52d009fc950b5c209260d50fcc000f5becd3c < e991457afdcb5f4dbc5bc9d79eaf775be33e7092 | e991457afdcb5f4dbc5bc9d79eaf775be33e7092 |
| linux | linux | >= dae52d009fc950b5c209260d50fcc000f5becd3c < b9a178f189bb6d75293573e181928735f5e3e070 | b9a178f189bb6d75293573e181928735f5e3e070 |
| linux | linux | >= dae52d009fc950b5c209260d50fcc000f5becd3c < 8d4abca95ecc82fc8c41912fa0085281f19cc29f | 8d4abca95ecc82fc8c41912fa0085281f19cc29f |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 2.6.34 < 4.4.277 | 4.4.277 |
| linux | linux_kernel | >= 4.10 < 4.14.241 | 4.14.241 |
| linux | linux_kernel | >= 4.15 < 4.19.199 | 4.19.199 |
| linux | linux_kernel | >= 4.20 < 5.4.136 | 5.4.136 |
| linux | linux_kernel | >= 4.5 < 4.9.277 | 4.9.277 |
| linux | linux_kernel | >= 5.11 < 5.13.6 | 5.13.6 |
| linux | linux_kernel | >= 5.5 < 5.10.54 | 5.10.54 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wxhc-3989-9jq8: In the Linux kernel, the following vulnerability has been resolved:
media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
Fix an 11
ghsa_unreviewed·2024-05-21
CVE-2021-47288 [HIGH] CWE-125 GHSA-wxhc-3989-9jq8: In the Linux kernel, the following vulnerability has been resolved:
media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
Fix an 11
In the Linux kernel, the following vulnerability has been resolved:
media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
Fix an 11-year old bug in ngene_command_config_free_buf() while
addressing the following warnings caught with -Warray-bounds:
arch/alpha/include/asm/string.h:22:16: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]
arch/x86/include/asm/string_32.h:182:25: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]
The problem is that the original code is trying to copy 6 bytes of
data into a one-byte size
OSV
CVE-2021-47288: In the Linux kernel, the following vulnerability has been resolved: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf() Fix an 11-y
osv·2024-05-21·CVSS 7.1
CVE-2021-47288 [HIGH] CVE-2021-47288: In the Linux kernel, the following vulnerability has been resolved: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf() Fix an 11-y
In the Linux kernel, the following vulnerability has been resolved: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf() Fix an 11-year old bug in ngene_command_config_free_buf() while addressing the following warnings caught with -Warray-bounds: arch/alpha/include/asm/string.h:22:16: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds] arch/x86/include/asm/string_32.h:182:25: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds] The problem is that the original code is trying to copy 6 bytes of data into a one-byte size memb
Red Hat
kernel: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
vendor_redhat·2024-05-21·CVSS 7.1
CVE-2021-47288 [HIGH] CWE-125 kernel: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
kernel: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
In the Linux kernel, the following vulnerability has been resolved:
media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
Fix an 11-year old bug in ngene_command_config_free_buf() while
addressing the following warnings caught with -Warray-bounds:
arch/alpha/include/asm/string.h:22:16: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]
arch/x86/include/asm/string_32.h:182:25: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]
The problem is th
Debian
CVE-2021-47288: linux - In the Linux kernel, the following vulnerability has been resolved: media: ngen...
vendor_debian·2021·CVSS 7.1
CVE-2021-47288 [HIGH] CVE-2021-47288: linux - In the Linux kernel, the following vulnerability has been resolved: media: ngen...
In the Linux kernel, the following vulnerability has been resolved: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf() Fix an 11-year old bug in ngene_command_config_free_buf() while addressing the following warnings caught with -Warray-bounds: arch/alpha/include/asm/string.h:22:16: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds] arch/x86/include/asm/string_32.h:182:25: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds] The problem is that the original code is trying to copy 6 bytes of data into a one-byte size memb
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/4487b968e5eacd02c493303dc2b61150bb7fe4b2https://git.kernel.org/stable/c/8d4abca95ecc82fc8c41912fa0085281f19cc29fhttps://git.kernel.org/stable/c/b9a178f189bb6d75293573e181928735f5e3e070https://git.kernel.org/stable/c/c6ddeb63dd543b5474b0217c4e47538b7ffd7686https://git.kernel.org/stable/c/e617fa62f6cf859a7b042cdd6c73af905ff8fca3https://git.kernel.org/stable/c/e818f2ff648581a6c553ae2bebc5dcef9a8bb90chttps://git.kernel.org/stable/c/e991457afdcb5f4dbc5bc9d79eaf775be33e7092https://git.kernel.org/stable/c/ec731c6ef564ee6fc101fc5d73e3a3a953d09a00https://git.kernel.org/stable/c/4487b968e5eacd02c493303dc2b61150bb7fe4b2https://git.kernel.org/stable/c/8d4abca95ecc82fc8c41912fa0085281f19cc29fhttps://git.kernel.org/stable/c/b9a178f189bb6d75293573e181928735f5e3e070https://git.kernel.org/stable/c/c6ddeb63dd543b5474b0217c4e47538b7ffd7686https://git.kernel.org/stable/c/e617fa62f6cf859a7b042cdd6c73af905ff8fca3https://git.kernel.org/stable/c/e818f2ff648581a6c553ae2bebc5dcef9a8bb90chttps://git.kernel.org/stable/c/e991457afdcb5f4dbc5bc9d79eaf775be33e7092https://git.kernel.org/stable/c/ec731c6ef564ee6fc101fc5d73e3a3a953d09a00
2024-05-21
Published