6.8

CVE-2021-33656

When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openatom ≫ Openeuler Version 20.03 Update - SwEdition lts
Openatom ≫ Openeuler Version 20.03 Update sp1 SwEdition lts
Openatom ≫ Openeuler Version 20.03 Update sp3 SwEdition lts
Linux ≫ Linux Kernel Version < 5.10.127
Debian ≫ Debian Linux Version 10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.435
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2022/07/19/3
Patch
Third Party Advisory
Mailing List
https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/releases/5.10.127/vt-drop-old-font-ioctls.patch
Patch
Third Party Advisory
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2021-33656&packageName=kernel
Third Party Advisory