CVE-2021-47352: virtio-net: Add validation for used length
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
The Linux kernel CVE team has assigned CVE-2021-47352 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024052141-CVE-2021-47352-df50@gregkh/T
Other sources
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
This adds validation for used length (might come from an untrusted device) to avoid data corruption or loss.
— MITRE
Linux Kernel is vulnerable to a denial of service, caused by not properly validate the length of data provided by an untrusted device in the virtio-net driver. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47352?
CVE-2021-47352 is classified as a high severity vulnerability in the Linux kernel.
How do I fix CVE-2021-47352?
To fix CVE-2021-47352, upgrade to kernel version 5.10.51, 5.12.18, 5.13.3, or 5.14.
What impact does CVE-2021-47352 have on affected systems?
CVE-2021-47352 could allow an attacker to manipulate network packet lengths, potentially leading to denial of service.
What Linux kernel versions are affected by CVE-2021-47352?
The affected Linux kernel versions for CVE-2021-47352 are prior to 5.10.51, 5.12.18, 5.13.3, and 5.14.
Is CVE-2021-47352 applicable to IBM Security Verify Governance?
Yes, CVE-2021-47352 affects IBM Security Verify Governance products up to version ISVG 10.0.2.