CVE-2021-37600

Description

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.054

Associated Vulnerability

VulnerabilityOS Platform
util-linux Security Update (ALAS-2023-1920) uuidd-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libuuid-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS-2023-1920) libuuid-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libblkid-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS-2023-1920) libblkid-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libfdisk-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS-2023-1920) libfdisk-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libmount-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS-2023-1920) libmount-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) util-linux-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS-2023-1920) util-linux-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libsmartcols-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS-2023-1920) libsmartcols-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libuuid-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libblkid-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libfdisk-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libmount-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) python-libmount-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) util-linux-user-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS-2023-1920) libsmartcols-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libfdisk-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libfdisk-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libfdisk-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libmount-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libmount-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libmount-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) python-libmount-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libblkid-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libblkid-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libblkid-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libsmartcols-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libsmartcols-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libsmartcols-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libuuid-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libuuid-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS2-2023-1920) libuuid-devel-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) util-linux-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) util-linux-2.30.2-2.amzn2.0.11.i686.rpmLinux
util-linux Security Update (ALAS2-2023-1920) util-linux-user-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
util-linux Security Update (ALAS2-2023-1920) uuidd-2.30.2-2.amzn2.0.11.x86_64.rpmLinux
Integer Overflow or Wraparound Vulnerability (CVE-2021-37600)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234