2024-05-21 16:03:24 +00:00
{
"id" : "CVE-2021-47404" ,
"sourceIdentifier" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"published" : "2024-05-21T15:15:25.920" ,
2024-12-24 17:03:42 +00:00
"lastModified" : "2024-12-24T16:05:42.447" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-05-21 16:03:24 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: betop: fix slab-out-of-bounds Write in betop_probe\n\nSyzbot reported slab-out-of-bounds Write bug in hid-betopff driver.\nThe problem is the driver assumes the device must have an input report but\nsome malicious devices violate this assumption.\n\nSo this patch checks hid_device's input is non empty before it's been used."
2024-05-26 02:03:22 +00:00
} ,
{
"lang" : "es" ,
"value" : " En el kernel de Linux, se resolvi\u00f3 la siguiente vulnerabilidad: HID: betop: corrige escritura slab-out-of-bounds en betop_probe. Syzbot inform\u00f3 un error de escritura slab-out-of-bounds en el controlador hid-betopff. El problema es que el controlador supone que el dispositivo debe tener un informe de entrada, pero algunos dispositivos maliciosos violan esta suposici\u00f3n. Entonces, este parche verifica que la entrada de hid_device no est\u00e9 vac\u00eda antes de usarse."
2024-05-21 16:03:24 +00:00
}
] ,
2024-12-24 17:03:42 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-787"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.4.286" ,
"matchCriteriaId" : "B91CAABE-0800-43BE-9D5D-D95C8E6C367B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.5" ,
"versionEndExcluding" : "4.9.285" ,
"matchCriteriaId" : "531DC051-E22F-4355-A06F-BE9AF2124AA3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.10" ,
"versionEndExcluding" : "4.14.249" ,
"matchCriteriaId" : "9DFC8239-9F26-43B2-A340-8EFC6BC6BDA8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.15" ,
"versionEndExcluding" : "4.19.209" ,
"matchCriteriaId" : "21C23429-F802-4256-B3C2-9EEA76AC11FF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.20" ,
"versionEndExcluding" : "5.4.151" ,
"matchCriteriaId" : "BFFC8E38-107A-4B6F-9FFD-9B2FD8B89EF0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.5" ,
"versionEndExcluding" : "5.10.71" ,
"matchCriteriaId" : "60C740E4-6C54-40CD-A914-2232D8FC781D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.11" ,
"versionEndExcluding" : "5.14.10" ,
"matchCriteriaId" : "1A437B0D-8305-4C72-B691-D26986A126CF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "E46C74C6-B76B-4C94-A6A4-FD2FFF62D644"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "60134C3A-06E4-48C1-B04F-2903732A4E56"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:5.15:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "0460DA88-8FE1-46A2-9DDA-1F1ABA552E71"
}
]
}
]
}
] ,
2024-05-21 16:03:24 +00:00
"references" : [
{
"url" : "https://git.kernel.org/stable/c/1c83c38dec83d57bc18d0c01d82c413d3b34ccb9" ,
2024-12-24 17:03:42 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-05-21 16:03:24 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/1e4ce418b1cb1a810256b5fb3fd33d22d1325993" ,
2024-12-24 17:03:42 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-05-21 16:03:24 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/6fc4476dda58f6c00097c7ddec3b772513f57525" ,
2024-12-24 17:03:42 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-05-21 16:03:24 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/708107b80aa616976d1c5fa60ac0c1390749db5e" ,
2024-12-24 17:03:42 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-05-21 16:03:24 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/a4faa7153b87fbcfe4be15f4278676f79ca6e019" ,
2024-12-24 17:03:42 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-05-21 16:03:24 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/bb8b72374db69afa25a5b65cf1c092860c6fe914" ,
2024-12-24 17:03:42 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-05-21 16:03:24 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/dedfc35a2de2bae9fa3da8210a05bfd515f83fee" ,
2024-12-24 17:03:42 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-05-21 16:03:24 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/fe9bb925e7096509711660d39c0493a1546e9550" ,
2024-12-24 17:03:42 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/1c83c38dec83d57bc18d0c01d82c413d3b34ccb9" ,
2024-12-24 17:03:42 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/1e4ce418b1cb1a810256b5fb3fd33d22d1325993" ,
2024-12-24 17:03:42 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/6fc4476dda58f6c00097c7ddec3b772513f57525" ,
2024-12-24 17:03:42 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/708107b80aa616976d1c5fa60ac0c1390749db5e" ,
2024-12-24 17:03:42 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/a4faa7153b87fbcfe4be15f4278676f79ca6e019" ,
2024-12-24 17:03:42 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/bb8b72374db69afa25a5b65cf1c092860c6fe914" ,
2024-12-24 17:03:42 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/dedfc35a2de2bae9fa3da8210a05bfd515f83fee" ,
2024-12-24 17:03:42 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/fe9bb925e7096509711660d39c0493a1546e9550" ,
2024-12-24 17:03:42 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
2024-05-21 16:03:24 +00:00
}
]
}