QSearchQSearch

CVE-2021-3612

7.8 HIGH

An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the ...

Published: 2021-07-09 · Last updated: 2026-06-17

Severity and scoring

CVSS
7.8 HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-20, CWE-787

Affected products

VendorProduct
debiancloud_backup, communications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function
fedoraprojectcloud_backup, communications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function
linuxcloud_backup, communications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function
netappcloud_backup, communications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function
oraclecloud_backup, communications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function
redhatcloud_backup, communications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function

Description

An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-1767 A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component (5.6 MEDIUM)
  • CVE-2026-1766 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 com... (5.6 MEDIUM)
  • CVE-2026-35273 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management) (9.8 CRITICAL)
  • CVE-2026-11793 A stack buffer overflow flaw was found in 389 Directory Server (4.9 MEDIUM)
  • CVE-2026-11790 A flaw was found in 389 Directory Server (4.9 MEDIUM)

Same CWE

  • CVE-2026-47750 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inf... (7.8 HIGH)
  • CVE-2026-47747 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inf... (7.8 HIGH)
  • CVE-2026-47749 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inf... (7.8 HIGH)
  • CVE-2026-12314 Memory safety bug fixed in Thunderbird 152 (7.5 HIGH)
  • CVE-2026-12310 Memory safety bug fixed in Thunderbird 152 (7.5 HIGH)