Related Vulnerabilities: CVE-2021-33655  

An out-of-bounds write flaw was found in the Linux kernel’s framebuffer-based console driver functionality in the way a user triggers ioctl FBIOPUT_VSCREENINFO with malicious data. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Description

An out-of-bounds write flaw was found in the Linux kernel’s framebuffer-based console driver functionality in the way a user triggers ioctl FBIOPUT_VSCREENINFO with malicious data. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Additional Information

  • Bugzilla 2108691: CVE-2021-33655 kernel: sending malicous data to kernel by ioctl FBIOPUT_VSCREENINFO may cause out of bounds write memory
  • CWE-787: Out-of-bounds Write
  • FAQ: Frequently asked questions about CVE-2021-33655