Review reviewCritical

CVE-2021-47478

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs image When isofs image is suitably corrupted isofs_read_inode() can read data beyond the end of buffer. Sanity-check the directory entry length before using it.

CVSS
9.1
EPSS
0.68%
48.9% percentile
CISA KEV
Not listed
Published
2024.05.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.68%
Technical severityCVSS 9.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs image When isofs image is suitably corrupted isofs_read_inode() can read data beyond the end of buffer. Sanity-check the directory entry length before using it.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 156ce5bb6cc43a80a743810199defb1dc3f55b7f, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9ec33a9b8790c212cc926a88c5e2105f97f3f57e, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < afbd40f425227e661d991757e11cc4db024e761f, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b0ddff8d68f2e43857a84dce54c3deab181c8ae1, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6e80e9314f8bb52d9eabe1907698718ff01120f5, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 86d4aedcbc69c0f84551fb70f953c24e396de2d7, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b2fa1f52d22c5455217b294629346ad23a744945, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e7fb722586a2936b37bdff096c095c30ca06404d, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e96a1866b40570b5950cda8602c2819189c62a48, >= 2.6.12, < 4.4.292, >= 4.5 < 4.9.290, >= 4.10 < 4.14.255, >= 4.15 < 4.19.217, >= 4.20 < 5.4.159, >= 5.5 < 5.10.79, >= 5.11 < 5.14.18, >= 5.15 < 5.15.2
Fixed versions
4.4.292, 4.9.290, 4.14.255, 4.19.217, 5.4.159, 5.10.79, 5.14.18, 5.15.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125
CVE-2021-47478 — Linux Linux, linux kernel | SECUFOCUS NOW