Name | CVE-2021-3743 |
Description | An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
References | DLA-2785-1, DSA-4978-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
linux (PTS) | stretch | 4.9.228-1 | fixed |
stretch (security) | 4.9.303-1 | fixed | |
buster | 4.19.235-1 | fixed | |
buster (security) | 4.19.232-1 | fixed | |
bullseye | 5.10.106-1 | fixed | |
bullseye (security) | 5.10.120-1 | fixed | |
bookworm, sid | 5.18.5-1 | fixed | |
linux-4.19 (PTS) | stretch (security) | 4.19.232-1~deb9u1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
linux | source | stretch | (not affected) | |||
linux | source | buster | 4.19.208-1 | |||
linux | source | bullseye | 5.10.46-5 | DSA-4978-1 | ||
linux | source | (unstable) | 5.14.6-1 | |||
linux-4.19 | source | stretch | 4.19.208-1~deb9u1 | DLA-2785-1 |
[stretch] - linux <not-affected> (Vulnerable code introduced later)
https://lists.openwall.net/netdev/2021/08/17/124
https://git.kernel.org/linus/7e78c597c3ebfd0cb329aa09a838734147e4f117