Out-of-bounds write in Linux kernel - CVE-2021-46974

 

Out-of-bounds write in Linux kernel - CVE-2021-46974

Published: June 18, 2024


Vulnerability identifier: #VU92191
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-46974
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to improper handling of masking negation logic upon a negative destination register. A local user can cause a denial of service by exploiting this flaw.


Affected software

Linux kernel
Storage Resource Manager
EMC Cloud Tiering Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway

How to mitigate CVE-2021-46974

Install updates from vendor's website.

Linux kernel - addressed in versions 4.14.233, 4.19.190, 5.4.117, 5.10.35, 5.11.19, 5.12.2
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Dell Secure Connect Gateway - update to 5.24.00.14
EMC Cloud Tiering Appliance - update to 13.2.0.2.29

External References

Related Security Bulletins