cbcvebase.
CVE-2021-47288
published 2024-05-21

CVE-2021-47288: In the Linux kernel, the following vulnerability has been resolved: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf() Fix an 11-year old…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf() Fix an 11-year old bug in ngene_command_config_free_buf() while addressing the following warnings caught with -Warray-bounds: arch/alpha/include/asm/string.h:22:16: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds] arch/x86/include/asm/string_32.h:182:25: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds] The problem is that the original code is trying to copy 6 bytes of data into a one-byte size member _config_ of the wrong structue FW_CONFIGURE_BUFFERS, in a single call to memcpy(). This causes a legitimate compiler warning because memcpy() overruns the length of &com.cmd.ConfigureBuffers.config. It seems that the right structure is FW_CONFIGURE_FREE_BUFFERS, instead, because it contains 6 more members apart from the header _hdr_. Also, the name of the function ngene_command_config_free_buf() suggests that the actual intention is to ConfigureFreeBuffers, instead of ConfigureBuffers (which takes place in the function ngene_command_config_buf(), above). Fix this by enclosing those 6 members of struct FW_CONFIGURE_FREE_BUFFERS into new struct config, and use &com.cmd.ConfigureFreeBuffers.config as the destination address, instead of &com.cmd.ConfigureBuffers.config, when calling memcpy(). This also helps with the ongoing efforts to globally enable -Warray-bounds and get us closer to being able to tighten the FORTIFY_SOURCE routines on memcpy().

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= dae52d009fc950b5c209260d50fcc000f5becd3c < 4487b968e5eacd02c493303dc2b61150bb7fe4b24487b968e5eacd02c493303dc2b61150bb7fe4b2
linuxlinux>= dae52d009fc950b5c209260d50fcc000f5becd3c < c6ddeb63dd543b5474b0217c4e47538b7ffd7686c6ddeb63dd543b5474b0217c4e47538b7ffd7686
linuxlinux>= dae52d009fc950b5c209260d50fcc000f5becd3c < e818f2ff648581a6c553ae2bebc5dcef9a8bb90ce818f2ff648581a6c553ae2bebc5dcef9a8bb90c
linuxlinux>= dae52d009fc950b5c209260d50fcc000f5becd3c < ec731c6ef564ee6fc101fc5d73e3a3a953d09a00ec731c6ef564ee6fc101fc5d73e3a3a953d09a00
linuxlinux>= dae52d009fc950b5c209260d50fcc000f5becd3c < e617fa62f6cf859a7b042cdd6c73af905ff8fca3e617fa62f6cf859a7b042cdd6c73af905ff8fca3
linuxlinux>= dae52d009fc950b5c209260d50fcc000f5becd3c < e991457afdcb5f4dbc5bc9d79eaf775be33e7092e991457afdcb5f4dbc5bc9d79eaf775be33e7092
linuxlinux>= dae52d009fc950b5c209260d50fcc000f5becd3c < b9a178f189bb6d75293573e181928735f5e3e070b9a178f189bb6d75293573e181928735f5e3e070
linuxlinux>= dae52d009fc950b5c209260d50fcc000f5becd3c < 8d4abca95ecc82fc8c41912fa0085281f19cc29f8d4abca95ecc82fc8c41912fa0085281f19cc29f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 2.6.34 < 4.4.2774.4.277
linuxlinux_kernel>= 4.10 < 4.14.2414.14.241
linuxlinux_kernel>= 4.15 < 4.19.1994.19.199
linuxlinux_kernel>= 4.20 < 5.4.1365.4.136
linuxlinux_kernel>= 4.5 < 4.9.2774.9.277
linuxlinux_kernel>= 5.11 < 5.13.65.13.6
linuxlinux_kernel>= 5.5 < 5.10.545.10.54

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.