CVE-2021-3743
Summary
| CVE | CVE-2021-3743 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-04 16:15:00 UTC |
| Updated | 2023-11-09 14:44:00 UTC |
| Description | An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-3743 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| oss-security - Re: Linux kernel: qrtr: another out-of-bound Read in
qrtr_endpoint_post in net/qrtr/qrtr.c |
MISC |
www.openwall.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| 1997961 – (CVE-2021-3743) CVE-2021-3743 kernel: out-of-bound Read in qrtr_endpoint_post in net/qrtr/qrtr.c |
MISC |
bugzilla.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| net: qrtr: fix another OOB Read in qrtr_endpoint_post · torvalds/linux@7e78c59 · GitHub |
MISC |
github.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| kernel/git/netdev/net.git - Netdev Group's networking tree |
MISC |
git.kernel.org |
|
| netdev - Another out-of-bound Read in qrtr_endpoint_post in net/qrtr/qrtr.c |
MISC |
lists.openwall.net |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159421 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9474)
- 159422 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel-container (ELSA-2021-9475)
- 159825 Oracle Enterprise Linux Security Update for kernel (ELSA-2022-1988)
- 178809 Debian Security Update for linux (DSA 4978-1)
- 178844 Debian Security Update for linux-4.19 (DLA 2785-1)
- 179558 Debian Security Update for linux (CVE-2021-3743)
- 198540 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5113-1)
- 198542 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5115-1)
- 198543 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5117-1)
- 198562 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5136-1)
- 198563 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5137-1)
- 198565 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5137-2)
- 240275 Red Hat Update for kernel-rt (RHSA-2022:1975)
- 240298 Red Hat Update for kernel security (RHSA-2022:1988)
- 377181 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2022:0022)
- 610418 Google Pixel Android June 2022 Security Patch Missing
- 610422 Google Android July 2022 Security Patch Missing for Huawei EMUI
- 671134 EulerOS Security Update for kernel (EulerOS-SA-2021-2688)
- 671137 EulerOS Security Update for kernel (EulerOS-SA-2021-2713)
- 751137 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:1271-1)
- 751160 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3179-1)
- 751170 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3205-1)
- 901158 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8921-1)
- 906366 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8921-2)
- 940517 AlmaLinux Security Update for kernel (ALSA-2022:1988)