CVE-2021-47509
published 2024-05-24CVE-2021-47509: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Limit the period size to 16MB Set the practical limit to the period size…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: oss: Limit the period size to 16MB
Set the practical limit to the period size (the fragment shift in OSS)
instead of a full 31bit; a too large value could lead to the exhaust
of memory as we allocate temporary buffers of the period size, too.
As of this patch, we set to 16MB limit, which should cover all use
cases.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d1bb703ad050de9095f10b2d3416c32921ac6bcc | d1bb703ad050de9095f10b2d3416c32921ac6bcc |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b02a41eebcc36d4f07196780f2e165ca2c499257 | b02a41eebcc36d4f07196780f2e165ca2c499257 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < be55f306396cd62c6889286a7194fd8b53363aeb | be55f306396cd62c6889286a7194fd8b53363aeb |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2e54cf6794bf82a54aaefc78da13819aea9cd28a | 2e54cf6794bf82a54aaefc78da13819aea9cd28a |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 76f19e4cbb548e28547f8c328aa0bfb3a10222d3 | 76f19e4cbb548e28547f8c328aa0bfb3a10222d3 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ad45babf7886e7a212ee1d5eda9ef49f696db43c | ad45babf7886e7a212ee1d5eda9ef49f696db43c |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 35a3e511032146941085f87dd9fb5b82ea5c00a2 | 35a3e511032146941085f87dd9fb5b82ea5c00a2 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8839c8c0f77ab8fc0463f4ab8b37fca3f70677c2 | 8839c8c0f77ab8fc0463f4ab8b37fca3f70677c2 |
| linux | linux_kernel | < 4.4.295 | 4.4.295 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 4.10 < 4.14.258 | 4.14.258 |
| linux | linux_kernel | >= 4.15 < 4.19.221 | 4.19.221 |
| linux | linux_kernel | >= 4.20 < 5.4.165 | 5.4.165 |
| linux | linux_kernel | >= 4.5 < 4.9.293 | 4.9.293 |
| linux | linux_kernel | >= 5.11 < 5.15.8 | 5.15.8 |
| linux | linux_kernel | >= 5.5 < 5.10.85 | 5.10.85 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ALSA: pcm: oss: Limit the period size to 16MB
vendor_redhat·2024-05-24·CVSS 5.5
CVE-2021-47509 [MEDIUM] CWE-400 kernel: ALSA: pcm: oss: Limit the period size to 16MB
kernel: ALSA: pcm: oss: Limit the period size to 16MB
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: oss: Limit the period size to 16MB
Set the practical limit to the period size (the fragment shift in OSS)
instead of a full 31bit; a too large value could lead to the exhaust
of memory as we allocate temporary buffers of the period size, too.
As of this patch, we set to 16MB limit, which should cover all use
cases.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Ente
Debian
CVE-2021-47509: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: ...
vendor_debian·2021·CVSS 5.5
CVE-2021-47509 [MEDIUM] CVE-2021-47509: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: ...
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Limit the period size to 16MB Set the practical limit to the period size (the fragment shift in OSS) instead of a full 31bit; a too large value could lead to the exhaust of memory as we allocate temporary buffers of the period size, too. As of this patch, we set to 16MB limit, which should cover all use cases.
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.92-1)
forky: resolved (fixed in 5.15.15-1)
sid: resolved (fixed in 5.15.15-1)
trixie: resolved (fixed in 5.15.15-1)
OSV
CVE-2021-47509: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Limit the period size to 16MB Set the practical limit to the perio
osv·2024-05-24·CVSS 5.5
CVE-2021-47509 [MEDIUM] CVE-2021-47509: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Limit the period size to 16MB Set the practical limit to the perio
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Limit the period size to 16MB Set the practical limit to the period size (the fragment shift in OSS) instead of a full 31bit; a too large value could lead to the exhaust of memory as we allocate temporary buffers of the period size, too. As of this patch, we set to 16MB limit, which should cover all use cases.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2e54cf6794bf82a54aaefc78da13819aea9cd28ahttps://git.kernel.org/stable/c/35a3e511032146941085f87dd9fb5b82ea5c00a2https://git.kernel.org/stable/c/76f19e4cbb548e28547f8c328aa0bfb3a10222d3https://git.kernel.org/stable/c/8839c8c0f77ab8fc0463f4ab8b37fca3f70677c2https://git.kernel.org/stable/c/ad45babf7886e7a212ee1d5eda9ef49f696db43chttps://git.kernel.org/stable/c/b02a41eebcc36d4f07196780f2e165ca2c499257https://git.kernel.org/stable/c/be55f306396cd62c6889286a7194fd8b53363aebhttps://git.kernel.org/stable/c/d1bb703ad050de9095f10b2d3416c32921ac6bcchttps://git.kernel.org/stable/c/2e54cf6794bf82a54aaefc78da13819aea9cd28ahttps://git.kernel.org/stable/c/35a3e511032146941085f87dd9fb5b82ea5c00a2https://git.kernel.org/stable/c/76f19e4cbb548e28547f8c328aa0bfb3a10222d3https://git.kernel.org/stable/c/8839c8c0f77ab8fc0463f4ab8b37fca3f70677c2https://git.kernel.org/stable/c/ad45babf7886e7a212ee1d5eda9ef49f696db43chttps://git.kernel.org/stable/c/b02a41eebcc36d4f07196780f2e165ca2c499257https://git.kernel.org/stable/c/be55f306396cd62c6889286a7194fd8b53363aebhttps://git.kernel.org/stable/c/d1bb703ad050de9095f10b2d3416c32921ac6bcc
2024-05-24
Published