Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-47458— ocfs2: mount fails with buffer overflow in strlen

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在缓冲区溢出漏洞。

CVSS 7.1 · High EPSS 0.25% · P16

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux c74a3bdd9b529d924d1abf986079b783dd105ace< ac011cb3ff7a76b3e0e6e77158ee4ba2f929e1fb affected
c74a3bdd9b529d924d1abf986079b783dd105ace< 4b74ddcc22ee6455946e80a9c4808801f8f8561e affected
c74a3bdd9b529d924d1abf986079b783dd105ace< 232ed9752510de4436468b653d145565669c8498 affected
c74a3bdd9b529d924d1abf986079b783dd105ace< 7623b1035ca2d17bde0f6a086ad6844a34648df1 affected
c74a3bdd9b529d924d1abf986079b783dd105ace< d3a83576378b4c904f711598dde2c5e881c4295c affected
c74a3bdd9b529d924d1abf986079b783dd105ace< 93be0eeea14cf39235e585c8f56df3b3859deaad affected
c74a3bdd9b529d924d1abf986079b783dd105ace< 0e677ea5b7396f715a76b6b0ef441430e4c4b57f affected
c74a3bdd9b529d924d1abf986079b783dd105ace< b15fa9224e6e1239414525d8d556d824701849fc affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-47458

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ocfs2: mount fails with buffer overflow in strlen
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ocfs2: mount fails with buffer overflow in strlen Starting with kernel 5.11 built with CONFIG_FORTIFY_SOURCE mouting an ocfs2 filesystem with either o2cb or pcmk cluster stack fails with the trace below. Problem seems to be that strings for cluster stack and cluster name are not guaranteed to be null terminated in the disk representation, while strlcpy assumes that the source string is always null terminated. This causes a read outside of the source string triggering the buffer overflow detection. detected buffer overflow in strlen ------------[ cut here ]------------ kernel BUG at lib/string.c:1149! invalid opcode: 0000 [#1] SMP PTI CPU: 1 PID: 910 Comm: mount.ocfs2 Not tainted 5.14.0-1-amd64 #1 Debian 5.14.6-2 RIP: 0010:fortify_panic+0xf/0x11 ... Call Trace: ocfs2_initialize_super.isra.0.cold+0xc/0x18 [ocfs2] ocfs2_fill_super+0x359/0x19b0 [ocfs2] mount_bdev+0x185/0x1b0 legacy_get_tree+0x27/0x40 vfs_get_tree+0x25/0xb0 path_mount+0x454/0xa20 __x64_sys_mount+0x103/0x140 do_syscall_64+0x3b/0xc0 entry_SYSCALL_64_after_hwframe+0x44/0xae
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在缓冲区溢出漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux c74a3bdd9b529d924d1abf986079b783dd105ace ~ ac011cb3ff7a76b3e0e6e77158ee4ba2f929e1fb -
Linux Linux 3.14 -

II. Public POCs for CVE-2021-47458

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-47458

登录查看更多情报信息。

Other References for CVE-2021-47458 (8)

Same Patch Batch · Linux · 2024-05-22 · 63 CVEs total

CVE-2021-47496 9.8 CRITICAL net/tls: Fix flipped sign in tls_err_abort() calls
CVE-2021-47478 9.1 CRITICAL isofs: Fix out of bound access for corrupted isofs image
CVE-2021-47450 8.8 HIGH KVM: arm64: Fix host stage-2 PGD refcount
CVE-2021-47433 8.1 HIGH btrfs: fix abort logic in btrfs_replace_file_extents
CVE-2021-47446 7.8 HIGH drm/msm/a4xx: fix error handling in a4xx_gpu_init()
CVE-2021-47493 7.8 HIGH ocfs2: fix race between searching chunks and release journal_head from buffer_head
CVE-2021-47492 7.8 HIGH mm, thp: bail out early in collapse_file for writeback page
CVE-2021-47494 7.8 HIGH cfg80211: fix management registrations locking
CVE-2021-47451 7.8 HIGH netfilter: xt_IDLETIMER: fix panic that occurs when timer_type has garbage value
CVE-2021-47447 7.8 HIGH drm/msm/a3xx: fix error handling in a3xx_gpu_init()
CVE-2021-47485 7.8 HIGH IB/qib: Protect from buffer overflow in struct qib_user_sdma_pkt fields
CVE-2021-47483 7.8 HIGH regmap: Fix possible double-free in regcache_rbtree_exit()
CVE-2021-47459 7.8 HIGH can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv
CVE-2021-47461 7.8 HIGH userfaultfd: fix a race between writeprotect and exit_mmap()
CVE-2021-47448 7.5 HIGH mptcp: fix possible stall on recvmsg()
CVE-2021-47438 7.1 HIGH net/mlx5e: Fix memory leak in mlx5_core_destroy_cq() error path
CVE-2021-47465 7.1 HIGH KVM: PPC: Book3S HV: Fix stack handling in idle_kvm_start_guest()
CVE-2021-47479 staging: rtl8712: fix use-after-free in rtl8712_dl_fw
CVE-2021-47475 comedi: vmk80xx: fix transfer-buffer overflows
CVE-2021-47498 dm rq: don't queue request to blk-mq during DM suspend

Showing top 20 of 63 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2021-47458

No comments yet


Leave a comment