CVE-2021-36086: Use After Free
SELinux Project SELinux is vulnerable to a denial of service, caused by a use-after-free in cilresetclasspermission . By sending a specially-crafted request, a local attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
The CIL compiler in SELinux 3.2 has a use-after-free in cilresetclasspermission (called from cilresetclasspermsset and cilresetclasspermslist).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36086.
What is the severity of CVE-2021-36086?
The severity of CVE-2021-36086 is medium with a severity value of 6.2.
How does CVE-2021-36086 affect SELinux Project SELinux?
CVE-2021-36086 affects SELinux Project SELinux by causing a denial of service through a use-after-free in cil_reset_classpermission.
How can I fix CVE-2021-36086 for IBM QRadar SIEM version 7.5.0 GA?
You can fix CVE-2021-36086 for IBM QRadar SIEM version 7.5.0 GA by applying the patch available at this URL: [link].
How can I fix CVE-2021-36086 for IBM QRadar SIEM version 7.4.3 GA - 7.4.3 FP4?
You can fix CVE-2021-36086 for IBM QRadar SIEM version 7.4.3 GA - 7.4.3 FP4 by applying the patch available at this URL: [link].
How can I fix CVE-2021-36086 for IBM QRadar SIEM version 7.3.3 GA - 7.3.3 FP10?
You can fix CVE-2021-36086 for IBM QRadar SIEM version 7.3.3 GA - 7.3.3 FP10 by applying the patch available at this URL: [link].
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-36086?
The Common Weakness Enumeration (CWE) ID for CVE-2021-36086 is 416.