CVE-2021-33909
Summary
| CVE | CVE-2021-33909 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-20 19:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05. |
Risk And Classification
Problem Types: CWE-787 | CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Application | Netapp | Hci Management Node | - | All | All | All |
| Application | Netapp | Solidfire | - | All | All | All |
| Application | Oracle | Communications Session Border Controller | 8.2 | All | All | All |
| Application | Oracle | Communications Session Border Controller | 8.3 | All | All | All |
| Application | Oracle | Communications Session Border Controller | 8.4 | All | All | All |
| Application | Oracle | Communications Session Border Controller | 9.0 | All | All | All |
| Hardware | Sonicwall | Sma1000 | - | All | All | All |
| Operating System | Sonicwall | Sma1000 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sequoia: A Deep Root In Linux's Filesystem Layer ≈ Packet Storm | MISC | packetstormsecurity.com | |
| [SECURITY] [DLA 2713-2] linux security update | MLIST | lists.debian.org | |
| [SECURITY] [DLA 2713-1] linux security update | MLIST | lists.debian.org | |
| oss-security - Re: CVE-2021-33909: size_t-to-int vulnerability in Linux's filesystem layer | MLIST | www.openwall.com | |
| oss-security - Re: Containers-optimized OS (COS) membership in the linux-distros list | MLIST | www.openwall.com | |
| Kernel Live Patch Security Notice LSN-0081-1 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| oss-security - Re: Containers-optimized OS (COS) membership in the linux-distros list | MLIST | www.openwall.com | |
| CVE-2021-33909 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [SECURITY] Fedora 34 Update: kernel-5.13.4-200.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Kernel Live Patch Security Notice LSN-0079-1 ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory |
| oss-security - Re: CVE-2021-33909: size_t-to-int vulnerability in Linux's filesystem layer | MLIST | www.openwall.com | |
| Oracle Critical Patch Update Advisory - January 2022 | MISC | www.oracle.com | |
| oss-security - CVE-2021-33909: size_t-to-int vulnerability in Linux's filesystem layer | MISC | www.openwall.com | |
| Kernel Live Patch Security Notice LSN-0083-1 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Debian -- Security Information -- DSA-4941-1 linux | DEBIAN | www.debian.org | |
| seq_file: disallow extremely large seq buffer allocations · torvalds/linux@8cae8cd · GitHub | CONFIRM | github.com | |
| [SECURITY] [DLA 2714-1] linux-4.19 security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 34 Update: kernel-5.13.4-200.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Security Advisory | CONFIRM | psirt.global.sonicwall.com | |
| oss-security - Containers-optimized OS (COS) membership in the linux-distros list | MLIST | www.openwall.com | |
| cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.4 | CONFIRM | cdn.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159308 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-2714)
- 159310 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-2725)
- 159315 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9368)
- 159316 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9369)
- 159317 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel-container (ELSA-2021-9370)
- 159318 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9371)
- 159319 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel-container (ELSA-2021-9372)
- 159322 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-9374)
- 159332 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9395)
- 159338 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9404)
- 159339 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel-container (ELSA-2021-9406)
- 159340 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9407)
- 159341 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel-container (ELSA-2021-9410)
- 178710 Debian Security Update for linux (DSA 4941-1)
- 178712 Debian Security Update for linux (DLA 2713-1)
- 178713 Debian Security Update for linux-4.19 (DLA 2714-1)
- 178714 Debian Security Update for linux (DLA 2713-2)
- 179494 Debian Security Update for linux (CVE-2021-33909)
- 198435 Ubuntu Security Notification for Linux kernel vulnerability (USN-5014-1) (Sequoia)
- 198436 Ubuntu Security Notification for Linux kernel (OEM) vulnerabilities (USN-5015-1) (Sequoia)
- 198437 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-5016-1) (Sequoia)
- 198438 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-5017-1) (Sequoia)
- 198459 Ubuntu Security Notification for Linux, Linux-aws, Linux-aws-hwe, Linux-azure, Linux-azure-4.15, Linux-gcp, (USN-5018-1)
- 239495 Red Hat Update for kpatch-patch (RHSA-2021:2727) (Sequoia)
- 239497 Red Hat Update for kpatch-patch (RHSA-2021:2723) (Sequoia)
- 239498 Red Hat Update for kernel (RHSA-2021:2722) (Sequoia)
- 239500 Red Hat Update for kpatch-patch (RHSA-2021:2720) (Sequoia)
- 239501 Red Hat Update for kernel-rt (RHSA-2021:2719) (Sequoia)
- 239502 Red Hat Update for kernel (RHSA-2021:2718) (Sequoia)
- 239504 Red Hat Update for kpatch-patch (RHSA-2021:2716) (Sequoia)
- 239505 Red Hat Update for kernel-rt (RHSA-2021:2715) (Sequoia)
- 239506 Red Hat Update for kernel (RHSA-2021:2714) (Sequoia)
- 239520 Red Hat Update for OpenShift Container Platform 4.7.21 (RHSA-2021:2763)
- 239521 Red Hat Update for kpatch-patch (RHSA-2021:2729)
- 239522 Red Hat Update for kernel (RHSA-2021:2728)
- 239523 Red Hat Update for kernel-rt (RHSA-2021:2726)
- 239524 Red Hat Update for kernel (RHSA-2021:2725)
- 257100 CentOS Security Update for kernel (CESA-2021:2725)
- 281734 Fedora Security Update for kernel (FEDORA-2021-07dc0b3eb1)
- 352491 Amazon Linux Security Advisory for kernel: ALAS-2021-1524
- 352493 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-059
- 352494 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-058
- 352495 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-057
- 352496 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-056
- 352497 Amazon Linux Security Advisory for kernel-livepatch: ALAS2LIVEPATCH-2021-055
- 352500 Amazon Linux Security Advisory for kernel: ALAS2-2021-1691
- 352828 Amazon Linux Security Advisory for kernel: ALAC2012-2021-027
- 352829 Amazon Linux Security Advisory for kmod-sfc: ALAC2012-2021-028
- 352830 Amazon Linux Security Advisory for kmod-mlx5: ALAC2012-2021-029
- 352831 Amazon Linux Security Advisory for kernel: ALAC2012-2021-030
- 352832 Amazon Linux Security Advisory for kmod-sfc: ALAC2012-2021-031
- 352833 Amazon Linux Security Advisory for kmod-mlx5: ALAC2012-2021-032
- 353146 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2022-005
- 353157 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-003
- 375710 Linux Kernel Local Privilege Escalation Vulnerability (Sequoia)
- 390220 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2021-0025)
- 390224 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2021-0023)
- 610386 Google Android Devices December 2021 Security Patch Missing
- 610391 Google Android January 2022 Security Patch Missing for Samsung
- 610392 Google Android January 2022 Security Patch Missing for Huawei EMUI
- 6140208 AWS Bottlerocket Security Update for kernel (GHSA-73f7-3962-2mrj)
- 670707 EulerOS Security Update for kernel (EulerOS-SA-2021-2465)
- 670744 EulerOS Security Update for kernel (EulerOS-SA-2021-2502)
- 670949 EulerOS Security Update for kernel (EulerOS-SA-2021-2570)
- 671033 EulerOS Security Update for kernel (EulerOS-SA-2021-2569)
- 671047 EulerOS Security Update for kernel (EulerOS-SA-2021-2588)
- 730155 McAfee Web Gateway Multiple Vulnerabilities(WP-3580, WP-3656, WP-3815, WP-3878, WP-3882, WP-3934,WP-3935, WP-3936, WP-3999)
- 750844 SUSE Enterprise Linux Security Update for kernel (SUSE-SU-2021:2407-1)
- 750847 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:2409-1)
- 750848 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2416-1)(Sequoia)
- 750851 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:2415-1)(Sequoia)
- 750864 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2421-1)
- 750868 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2427-1)
- 750869 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2422-1)
- 750877 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:2427-1)
- 750880 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2451-1)
- 750887 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:1076-1)
- 750899 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (SUSE-SU-2021:2538-1)
- 751437 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3876-1)
- 751441 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3876-1)
- 900096 CBL-Mariner Linux Security Update for kernel 5.10.52.1
- 900304 CBL-Mariner Linux Security Update for kernel 5.10.57.1
- 900319 CBL-Mariner Linux Security Update for kernel 5.10.60.1
- 901371 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (6565-1)
- 903049 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (4638)
- 905954 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (4638-1)
- 940164 AlmaLinux Security Update for kernel (ALSA-2021:2714)
- 960070 Rocky Linux Security Update for kernel (RLSA-2021:2714)