CVE Database
/

CVE-2021-47240

Back to search

CVE-2021-47240

Published: May 21, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix OOB Read in qrtr_endpoint_post Syzbot reported slab-out-of-bounds Read in qrtr_endpoint_post. The problem was in wrong _size_ type: if (len != ALIGN(size, 4) + hdrlen) goto err; If size from qrtr_hdr is 4294967293 (0xfffffffd), the result of ALIGN(size, 4) will be 0. In case of len == hdrlen and size == 4294967293 in header this check won't fail and skb_put_data(skb, data + hdrlen, size); will read out of bound from data, which is hdrlen allocated block.

VendorProductVersions

Linux

Linux

affected
194ccc88297ae78d0803adad83c6dcc369787c9e - < f8111c0d7ed42ede41a3d0d393b104de0730a8a6
affected
194ccc88297ae78d0803adad83c6dcc369787c9e - < 26b8d10703a9be45d6097946b2b4011f7dd2c56f
affected
194ccc88297ae78d0803adad83c6dcc369787c9e - < 960b08dd36de1e341e3eb43d1c547513e338f4f8
affected
194ccc88297ae78d0803adad83c6dcc369787c9e - < 19892ab9c9d838e2e5a7744d36e4bb8b7c3292fe
affected
194ccc88297ae78d0803adad83c6dcc369787c9e - < ad9d24c9429e2159d1e279dc3a83191ccb4daf1d

Linux

Linux

affected
4.15
unaffected
0 - < 4.15
unaffected
4.19.196 - <= 4.19.*
unaffected
5.4.128 - <= 5.4.*
unaffected
5.10.46 - <= 5.10.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2021-47240 - Security Vulnerability | QwikSec