Vulnerabilities > CVE-2021-47240 - Out-of-bounds Read vulnerability in Linux Kernel
Summary
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix OOB Read in qrtr_endpoint_post Syzbot reported slab-out-of-bounds Read in qrtr_endpoint_post. The problem was in wrong _size_ type: if (len != ALIGN(size, 4) + hdrlen) goto err; If size from qrtr_hdr is 4294967293 (0xfffffffd), the result of ALIGN(size, 4) will be 0. In case of len == hdrlen and size == 4294967293 in header this check won't fail and skb_put_data(skb, data + hdrlen, size); will read out of bound from data, which is hdrlen allocated block.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Overread Buffers An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occurs when a value influencing where to start or stop reading is set to reflect positions outside of the valid memory location of the buffer. This type of attack may result in exposure of sensitive information, a system crash, or arbitrary code execution.
References
- https://git.kernel.org/stable/c/19892ab9c9d838e2e5a7744d36e4bb8b7c3292fe
- https://git.kernel.org/stable/c/19892ab9c9d838e2e5a7744d36e4bb8b7c3292fe
- https://git.kernel.org/stable/c/26b8d10703a9be45d6097946b2b4011f7dd2c56f
- https://git.kernel.org/stable/c/26b8d10703a9be45d6097946b2b4011f7dd2c56f
- https://git.kernel.org/stable/c/960b08dd36de1e341e3eb43d1c547513e338f4f8
- https://git.kernel.org/stable/c/960b08dd36de1e341e3eb43d1c547513e338f4f8
- https://git.kernel.org/stable/c/ad9d24c9429e2159d1e279dc3a83191ccb4daf1d
- https://git.kernel.org/stable/c/ad9d24c9429e2159d1e279dc3a83191ccb4daf1d
- https://git.kernel.org/stable/c/f8111c0d7ed42ede41a3d0d393b104de0730a8a6
- https://git.kernel.org/stable/c/f8111c0d7ed42ede41a3d0d393b104de0730a8a6