cbcvebase.
CVE-2021-47404
published 2024-05-21

CVE-2021-47404: In the Linux kernel, the following vulnerability has been resolved: HID: betop: fix slab-out-of-bounds Write in betop_probe Syzbot reported slab-out-of-bounds…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.8th percentile
In the Linux kernel, the following vulnerability has been resolved: HID: betop: fix slab-out-of-bounds Write in betop_probe Syzbot reported slab-out-of-bounds Write bug in hid-betopff driver. The problem is the driver assumes the device must have an input report but some malicious devices violate this assumption. So this patch checks hid_device's input is non empty before it's been used.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.12-1 (bookworm)linux 5.14.12-1 (bookworm)
linuxlinux
linuxlinux>= 52cd7785f3cdd2724f4efb5b21dbc75d6f9ccef4 < a4faa7153b87fbcfe4be15f4278676f79ca6e019a4faa7153b87fbcfe4be15f4278676f79ca6e019
linuxlinux>= 52cd7785f3cdd2724f4efb5b21dbc75d6f9ccef4 < 6fc4476dda58f6c00097c7ddec3b772513f575256fc4476dda58f6c00097c7ddec3b772513f57525
linuxlinux>= 52cd7785f3cdd2724f4efb5b21dbc75d6f9ccef4 < 1c83c38dec83d57bc18d0c01d82c413d3b34ccb91c83c38dec83d57bc18d0c01d82c413d3b34ccb9
linuxlinux>= 52cd7785f3cdd2724f4efb5b21dbc75d6f9ccef4 < bb8b72374db69afa25a5b65cf1c092860c6fe914bb8b72374db69afa25a5b65cf1c092860c6fe914
linuxlinux>= 52cd7785f3cdd2724f4efb5b21dbc75d6f9ccef4 < fe9bb925e7096509711660d39c0493a1546e9550fe9bb925e7096509711660d39c0493a1546e9550
linuxlinux>= 52cd7785f3cdd2724f4efb5b21dbc75d6f9ccef4 < dedfc35a2de2bae9fa3da8210a05bfd515f83feededfc35a2de2bae9fa3da8210a05bfd515f83fee
linuxlinux>= 52cd7785f3cdd2724f4efb5b21dbc75d6f9ccef4 < 708107b80aa616976d1c5fa60ac0c1390749db5e708107b80aa616976d1c5fa60ac0c1390749db5e
linuxlinux>= 52cd7785f3cdd2724f4efb5b21dbc75d6f9ccef4 < 1e4ce418b1cb1a810256b5fb3fd33d22d13259931e4ce418b1cb1a810256b5fb3fd33d22d1325993
linuxlinux_kernel< 4.4.2864.4.286
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 4.10 < 4.14.2494.14.249
linuxlinux_kernel>= 4.15 < 4.19.2094.19.209
linuxlinux_kernel>= 4.20 < 5.4.1515.4.151
linuxlinux_kernel>= 4.5 < 4.9.2854.9.285
linuxlinux_kernel>= 5.11 < 5.14.105.14.10
linuxlinux_kernel>= 5.5 < 5.10.715.10.71

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.