MEDIUM · 6.7

CVE-2021-42739

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles ...

Vulnerability Description

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 5.14.13
FedoraprojectFedora33
DebianDebian Linux9.0
StarwindsoftwareStarwind San \& Nasv8r12
StarwindsoftwareStarwind Virtual Sanv8r13
OracleCommunications Cloud Native Core Binding Support Function22.1.3
OracleCommunications Cloud Native Core Network Exposure Function22.1.1
OracleCommunications Cloud Native Core Policy22.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-42739?

CVE-2021-42739 is a vulnerability with a CVSS score of 6.7 (MEDIUM). The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles ...

How severe is CVE-2021-42739?

CVE-2021-42739 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-42739?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Debian Debian Linux, Starwindsoftware Starwind San \& Nas, Starwindsoftware Starwind Virtual San.