An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
References
| Link | Resource |
|---|---|
| https://lore.kernel.org/linux-input/20210620120030.1513655-1-avlarkin82@gmail.com/ | Exploit Mailing List Patch Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1974079 | Issue Tracking Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YKGI562LFV5MESTMVTCG5RORSBT6NGBN/ | Mailing List Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20210805-0005/ | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html | Mailing List Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2021-07-09 11:15
Updated : 2022-07-25 18:16
NVD link : CVE-2021-3612
Mitre link : CVE-2021-3612
JSON object : View
Products Affected
linux
- linux_kernel
debian
- debian_linux
fedoraproject
- fedora
redhat
- enterprise_linux
CWE
CWE-787
Out-of-bounds Write
