3.3

CVE-2021-36086

Exploit
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 11.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ H610c Firmware Version -
   Netapp ≫ H610c Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
Netapp ≫ H615c Firmware Version -
   Netapp ≫ H615c Version -
Selinux Project ≫ Selinux Version < 3.3
Fedoraproject ≫ Fedora Version 35
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.452
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
Broken Link
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32177
Patch
Third Party Advisory
Exploit
Issue Tracking
https://github.com/SELinuxProject/selinux/commit/c49a8ea09501ad66e799ea41b8154b6770fec2c8
Patch
Third Party Advisory
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-536.yaml
Third Party Advisory
https://security.netapp.com/advisory/ntap-20250207-0004/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/10/msg00021.html
Third Party Advisory
Mailing List