CVE-2021-37600: Integer Overflow
DISPUTED An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-37600.
What is the severity of CVE-2021-37600?
The severity of CVE-2021-37600 is medium (5.5).
What is the affected software?
The affected software is util-linux through 2.37.1 and NetApp ONTAP Select Deploy administration utility.
What is the fix for CVE-2021-37600?
There is currently no known fix for CVE-2021-37600. Please follow the official references for any updates or patches.
What are the references for CVE-2021-37600?
The references for CVE-2021-37600 are: [GitHub commit](https://github.com/karelzak/util-linux/commit/1c9143d0c1f979c3daf10e1c37b5b1e916c22a1c), [GitHub issue](https://github.com/karelzak/util-linux/issues/1395), [NetApp security advisory](https://security.netapp.com/advisory/ntap-20210902-0002/).