CVE-2021-42739

MEDIUM

Linux kernel < 5.14.13 - Out-of-bounds Write in Firewire Subsystem

Title source: llm
STIX 2.1

Description

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.

Scores

CVSS v3 6.7
EPSS 0.0011
EPSS Percentile 28.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (10)
debian/debian_linux 9.0
fedoraproject/fedora 33
fedoraproject/fedora 34
fedoraproject/fedora 35
linux/linux_kernel < 5.14.13
oracle/communications_cloud_native_core_binding_support_function 22.1.3
oracle/communications_cloud_native_core_network_exposure_function 22.1.1
oracle/communications_cloud_native_core_policy 22.2.0
starwindsoftware/starwind_san_\&_nas v8r12
starwindsoftware/starwind_virtual_san v8r13 14338
Published Oct 20, 2021
Tracked Since Feb 18, 2026