cbcvebase.
CVE-2021-47485
published 2024-05-22

CVE-2021-47485: In the Linux kernel, the following vulnerability has been resolved: IB/qib: Protect from buffer overflow in struct qib_user_sdma_pkt fields Overflowing either…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: IB/qib: Protect from buffer overflow in struct qib_user_sdma_pkt fields Overflowing either addrlimit or bytes_togo can allow userspace to trigger a buffer overflow of kernel memory. Check for overflows in all the places doing math on user controlled buffers.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.3-1 (bookworm)linux 5.15.3-1 (bookworm)
linuxlinux
linuxlinux>= f931551bafe1f10ded7f5282e2aa162c267a2e5d < bda41654b6e0c125a624ca35d6d20beb8015b5d0bda41654b6e0c125a624ca35d6d20beb8015b5d0
linuxlinux>= f931551bafe1f10ded7f5282e2aa162c267a2e5d < 3f57c3f67fd93b4da86aeffea1ca32c484d054ad3f57c3f67fd93b4da86aeffea1ca32c484d054ad
linuxlinux>= f931551bafe1f10ded7f5282e2aa162c267a2e5d < 60833707b968d5ae02a75edb7886dcd4a957cf0d60833707b968d5ae02a75edb7886dcd4a957cf0d
linuxlinux>= f931551bafe1f10ded7f5282e2aa162c267a2e5d < 73d2892148aa4397a885b4f4afcfc5b27a325c4273d2892148aa4397a885b4f4afcfc5b27a325c42
linuxlinux>= f931551bafe1f10ded7f5282e2aa162c267a2e5d < 0f8cdfff06829a0b0348b6debc29ff6a619677240f8cdfff06829a0b0348b6debc29ff6a61967724
linuxlinux>= f931551bafe1f10ded7f5282e2aa162c267a2e5d < c3e17e58f571f34c51aeb17274ed02c2ed5cf780c3e17e58f571f34c51aeb17274ed02c2ed5cf780
linuxlinux>= f931551bafe1f10ded7f5282e2aa162c267a2e5d < 0d4395477741608d123dad51def9fe50b7ebe9520d4395477741608d123dad51def9fe50b7ebe952
linuxlinux>= f931551bafe1f10ded7f5282e2aa162c267a2e5d < d39bf40e55e666b5905fdbd46a0dced030ce87bed39bf40e55e666b5905fdbd46a0dced030ce87be
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 0 < 4.4.0-277.3114.4.0-277.311
linuxlinux_kernel>= 2.6.35 < 4.4.2924.4.292
linuxlinux_kernel>= 4.10 < 4.14.2554.14.255
linuxlinux_kernel>= 4.15 < 4.19.2164.19.216
linuxlinux_kernel>= 4.20 < 5.4.1575.4.157
linuxlinux_kernel>= 4.5 < 4.9.2904.9.290
linuxlinux_kernel>= 5.11 < 5.14.165.14.16
linuxlinux_kernel>= 5.5 < 5.10.775.10.77

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.