CVE-2021-47352
published 2024-05-21CVE-2021-47352: In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (might come…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
This adds validation for used length (might come
from an untrusted device) to avoid data corruption
or loss.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= f6b10209b90d48a84f886ab2b317b5d2cbfe3143 < c1b40d1959517ff2ea473d40eeab4691d6d62462 | c1b40d1959517ff2ea473d40eeab4691d6d62462 |
| linux | linux | >= f6b10209b90d48a84f886ab2b317b5d2cbfe3143 < c92298d228f61589dd21657af2bea95fc866b813 | c92298d228f61589dd21657af2bea95fc866b813 |
| linux | linux | >= f6b10209b90d48a84f886ab2b317b5d2cbfe3143 < 3133e01514c3c498f2b01ff210ee6134b70c663c | 3133e01514c3c498f2b01ff210ee6134b70c663c |
| linux | linux | >= f6b10209b90d48a84f886ab2b317b5d2cbfe3143 < ba710baa1cc1b17a0483f7befe03e696efd17292 | ba710baa1cc1b17a0483f7befe03e696efd17292 |
| linux | linux | >= f6b10209b90d48a84f886ab2b317b5d2cbfe3143 < ad993a95c508417acdeb15244109e009e50d8758 | ad993a95c508417acdeb15244109e009e50d8758 |
| linux | linux_kernel | < 5.4.293 | 5.4.293 |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.12.18 | 5.12.18 |
| linux | linux_kernel | >= 5.13 < 5.13.3 | 5.13.3 |
| linux | linux_kernel | >= 5.5 < 5.10.51 | 5.10.51 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: virtio-net: Add validation for used length
vendor_redhat·2024-05-21·CVSS 7.8
CVE-2021-47352 [HIGH] CWE-20 kernel: virtio-net: Add validation for used length
kernel: virtio-net: Add validation for used length
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
This adds validation for used length (might come
from an untrusted device) to avoid data corruption
or loss.
A vulnerability was found in the Linux kernel’s virtio-net driver, where the system does not properly validate the length of data provided by an untrusted device. This lack of validation could lead to data corruption if the length of the data is incorrect or maliciously crafted.
Statement: This vulnerability is rated as a moderate severity because it involves potential data corruption or loss, but requires exploitation through specific conditions involving untrusted devices and does not directly impact system confidentia
Debian
CVE-2021-47352: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-net:...
vendor_debian·2021·CVSS 7.8
CVE-2021-47352 [HIGH] CVE-2021-47352: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-net:...
In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (might come from an untrusted device) to avoid data corruption or loss.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
GHSA
GHSA-hxcf-7gwm-65p8: In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
This adds validation for used length
ghsa_unreviewed·2024-05-21
CVE-2021-47352 [HIGH] CWE-787 GHSA-hxcf-7gwm-65p8: In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
This adds validation for used length
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
This adds validation for used length (might come
from an untrusted device) to avoid data corruption
or loss.
OSV
CVE-2021-47352: In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (m
osv·2024-05-21·CVSS 7.8
CVE-2021-47352 [HIGH] CVE-2021-47352: In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (m
In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (might come from an untrusted device) to avoid data corruption or loss.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3133e01514c3c498f2b01ff210ee6134b70c663chttps://git.kernel.org/stable/c/ad993a95c508417acdeb15244109e009e50d8758https://git.kernel.org/stable/c/ba710baa1cc1b17a0483f7befe03e696efd17292https://git.kernel.org/stable/c/c1b40d1959517ff2ea473d40eeab4691d6d62462https://git.kernel.org/stable/c/c92298d228f61589dd21657af2bea95fc866b813https://git.kernel.org/stable/c/3133e01514c3c498f2b01ff210ee6134b70c663chttps://git.kernel.org/stable/c/ad993a95c508417acdeb15244109e009e50d8758https://git.kernel.org/stable/c/ba710baa1cc1b17a0483f7befe03e696efd17292https://git.kernel.org/stable/c/c92298d228f61589dd21657af2bea95fc866b813
2024-05-21
Published