CVE-2021-47366 describes a data corruption vulnerability in the Linux kernel's AFS client when reading files between 2GB and 4GB from an OpenAFS server. This occurs because the client incorrectly uses a 32-bit signed value for file position in FS.FetchData RPCs, leading to sign extension issues. The vulnerability affects Linux kernel versions interacting with OpenAFS servers, causing data integrity problems such as corrupted git pack files. The vulnerability is rated Medium severity (CVSS 5.5) with a local attack vector and low attack complexity. The primary impact is high availability impact (A:H) due to data corruption, with no direct impact on confidentiality or integrity of the system itself. The issue is categorized under CWE-787 (Out-of-bounds Write). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.22, < 5.14.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.15:rc1:*:*:*:*:*:* | ||
5.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.15:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.