CVE-2021-33631: Kernel crash in EXT4 filesystem
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
Other sources
NVD description: Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
Upstream commit: https://github.com/torvalds/linux/commit/5c099c4fdc438014d5893629e70a8ba934433ee8
References: https://www.openwall.com/lists/oss-security/2024/01/30/3 https://nvd.nist.gov/vuln/detail/CVE-2021-33631
— Red Hat
openEuler is vulnerable to a denial of service, caused by an integer overflow. A local authenticated attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.2 - Upgrade
Upgrade
openEuler kernelto a version that resolves this vulnerability.Fixed in 4.19.90-2401.3 - Upgrade
Upgrade
openEuler kernelto a version that resolves this vulnerability.Fixed in 5.10.0-183.0.0 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.135-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33631?
CVE-2021-33631 has a medium severity rating due to the potential for an integer overflow leading to various security issues.
How do I fix CVE-2021-33631?
To remedy CVE-2021-33631, upgrade to the latest kernel versions or apply patches as recommended by your distribution.
Which products are affected by CVE-2021-33631?
CVE-2021-33631 affects openEuler kernel versions prior to 4.19.90-2401.3 and 5.10.0-183.0.0, as well as IBM QRadar SIEM 7.5 - 7.5.0 UP8 IF01.
Is my system vulnerable to CVE-2021-33631?
You may be vulnerable to CVE-2021-33631 if you are using affected versions of openEuler Linux or the specified IBM QRadar SIEM version.
What are the potential impacts of CVE-2021-33631?
Exploitation of CVE-2021-33631 could lead to system crashes or unauthorized access to sensitive data due to the forced integer overflow.