CVE-2021-36084: Use After Free
SELinux Project SELinux is vulnerable to a denial of service, caused by a use-after-free in cilverifyclassperms. By sending a specially-crafted request, a local attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
The CIL compiler in SELinux 3.2 has a use-after-free in cilverifyclassperms (called from cilverifyclasspermission and cilpreverifyhelper).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-36084?
CVE-2021-36084 is a vulnerability in SELinux that allows a local attacker to cause a denial of service.
How does CVE-2021-36084 work?
CVE-2021-36084 is caused by a use-after-free vulnerability in __cil_verify_classperms, which can be exploited by sending a specially-crafted request.
What is the severity of CVE-2021-36084?
The severity of CVE-2021-36084 is medium, with a CVSS score of 6.2.
How can I fix CVE-2021-36084 in IBM QRadar SIEM 7.5.0 GA?
To fix CVE-2021-36084 in IBM QRadar SIEM 7.5.0 GA, you can apply the patch available from IBM Support.
How can I fix CVE-2021-36084 in IBM QRadar SIEM 7.4.3 GA - 7.4.3 FP4?
To fix CVE-2021-36084 in IBM QRadar SIEM 7.4.3 GA - 7.4.3 FP4, you can apply the patch available from IBM Support.
How can I fix CVE-2021-36084 in IBM QRadar SIEM 7.3.3 GA - 7.3.3 FP10?
To fix CVE-2021-36084 in IBM QRadar SIEM 7.3.3 GA - 7.3.3 FP10, you can apply the patch available from IBM Support.