CVE-2021-3782
Summary
| CVE | CVE-2021-3782 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-23 16:15:00 UTC |
| Updated | 2023-11-07 03:38:00 UTC |
| Description | An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count is maintained as an int; on LP64 systems this can cause the reference count to overflow if the client creates a large number of wl_shm buffer objects, or if it can coerce the server to create a large number of external references to the buffer storage. With the reference count overflowing, a use-after-free can be constructed on the wl_shm_pool tracking structure, where values may be incremented or decremented; it may also be possible to construct a limited oracle to leak 4 bytes of server-side memory to the attacking client at a time. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Reference count overflow in shm leads to use-after-free (#224) · Issues · wayland / wayland · GitLab | MISC | gitlab.freedesktop.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160653 Oracle Enterprise Linux Security Update for wayland (ELSA-2023-2786)
- 182934 Debian Security Update for wayland (CVE-2021-3782)
- 198941 Ubuntu Security Notification for Wayland Vulnerability (USN-5614-1)
- 241495 Red Hat Update for wayland security (RHSA-2023:2786)
- 355417 Amazon Linux Security Advisory for wayland : ALAS2023-2023-203
- 355541 Amazon Linux Security Advisory for wayland : ALAS2-2023-2103
- 378640 Alibaba Cloud Linux Security Update for wayland (ALINUX3-SA-2023:0060)
- 672373 EulerOS Security Update for wayland (EulerOS-SA-2022-2749)
- 672382 EulerOS Security Update for wayland (EulerOS-SA-2022-2784)
- 672431 EulerOS Security Update for wayland (EulerOS-SA-2022-2862)
- 672450 EulerOS Security Update for wayland (EulerOS-SA-2022-2836)
- 672575 EulerOS Security Update for wayland (EulerOS-SA-2023-1343)
- 672749 EulerOS Security Update for wayland (EulerOS-SA-2023-1519)
- 753921 SUSE Enterprise Linux Security Update for wayland (SUSE-SU-2023:1874-1)
- 753922 SUSE Enterprise Linux Security Update for wayland (SUSE-SU-2023:1873-1)
- 755882 SUSE Enterprise Linux Security Update for wayland (SUSE-SU-2023:1864-1)
- 904051 Common Base Linux Mariner (CBL-Mariner) Security Update for wayland (11019)
- 904054 Common Base Linux Mariner (CBL-Mariner) Security Update for wayland (11024)
- 904249 Common Base Linux Mariner (CBL-Mariner) Security Update for wayland (11019-1)
- 904509 Common Base Linux Mariner (CBL-Mariner) Security Update for wayland (11024-1)
- 941086 AlmaLinux Security Update for wayland (ALSA-2023:2786)