CVE-2021-42739

Advisory lineage Upstream: 0 Downstream: 58
Modified
Published: 20 Oct 2021, 00:00
Last modified:04 Aug 2024, 03:38

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.7 MEDIUM
v3.1 (nvd)
EPSS Score
0.11% LOW
0% probability +0.07%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Oct 2021, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 03:38
Last Modified
Vulnerability information updated

Description

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.

CVSS Metrics

  • v3.1MEDIUMScore: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.11% Percentile: 29%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    33 | 34 | 35

  • linuxlinux_kernel

    ≤ 5.14.13

  • oraclecommunications_cloud_native_core_binding_support_function

    22.1.3

  • oraclecommunications_cloud_native_core_network_exposure_function

    22.1.1

  • oraclecommunications_cloud_native_core_policy

    22.2.0

  • starwindsoftwarestarwind_san_\&_nas

    v8r12

  • starwindsoftwarestarwind_virtual_san

    v8r13:14338

References (6)