CVE-2021-47040

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 28, 2024
Updated: Jan 9, 2025
CWE ID 120

Summary

CVE-2021-47040 is a recently addressed vulnerability in the Linux kernel. It affected the nio_uring component where issues with overflows in the provide buffers were identified. Colin reported potential overflow and sign extension problems in the function io_provide_buffers_prep(). Linus Torvalds acknowledged previous attempts to resolve the issue were ineffective. The vulnerability was mitigated by implementing check_<op>_overflow helpers and refining the definition of struct nio_provide_buf's len type, which was found to be ineffective in its previous signed state.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share