Out-of-bounds Read Affecting python3-perf-debuginfo package, versions <0:4.18.0-372.9.1.el8
Threat Intelligence
EPSS
0.08% (34th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ROCKY8-PYTHON3PERFDEBUGINFO-3194462
- published 5 Jan 2023
- disclosed 4 Nov 2021
Introduced: 4 Nov 2021
CVE-2021-43389 Open this link in a new tabHow to fix?
Upgrade Rocky-Linux:8
python3-perf-debuginfo
to version 0:4.18.0-372.9.1.el8 or higher.
This issue was patched in RLSA-2022:1988
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3-perf-debuginfo
package and not the python3-perf-debuginfo
package as distributed by Rocky-Linux
.
See How to fix?
for Rocky-Linux:8
relevant fixed versions and status.
An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43389
- https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-43389.json
- http://www.openwall.com/lists/oss-security/2021/11/05/1
- https://bugzilla.redhat.com/show_bug.cgi?id=2013180
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.15
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1f3e2e97c003f80c4b087092b225c8787ff91e4d
- https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- https://lore.kernel.org/netdev/CAFcO6XOvGQrRTaTkaJ0p3zR7y7nrAWD79r48=L_BbOyrK9X-vA@mail.gmail.com/
- https://seclists.org/oss-sec/2021/q4/39
- https://www.debian.org/security/2022/dsa-5096
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://lore.kernel.org/netdev/CAFcO6XOvGQrRTaTkaJ0p3zR7y7nrAWD79r48=L_BbOyrK9X-vA%40mail.gmail.com/
CVSS Scores
version 3.1