QSearchQSearch

CVE-2021-42739

6.7 MEDIUM

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and driv...

Published: 2021-10-20 · Last updated: 2026-06-17

Severity and scoring

CVSS
6.7 MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-787

Affected products

VendorProduct
debiancommunications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function, communications_cloud_native_core_policy
fedoraprojectcommunications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function, communications_cloud_native_core_policy
linuxcommunications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function, communications_cloud_native_core_policy
oraclecommunications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function, communications_cloud_native_core_policy
starwindsoftwarecommunications_cloud_native_core_binding_support_function, communications_cloud_native_core_network_exposure_function, communications_cloud_native_core_policy

Description

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-35273 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management) (9.8 CRITICAL)
  • CVE-2026-49975 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP ... (7.5 HIGH)
  • CVE-2026-46273 In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapt... (8.6 HIGH)
  • CVE-2026-46272 In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysfs and perf mode ... (4.7 MEDIUM)
  • CVE-2026-46271 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link In case of multi... (7.8 HIGH)

Same CWE

  • CVE-2026-47750 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inf... (7.8 HIGH)
  • CVE-2026-47747 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inf... (7.8 HIGH)
  • CVE-2026-47749 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inf... (7.8 HIGH)
  • CVE-2026-12314 Memory safety bug fixed in Thunderbird 152 (7.5 HIGH)
  • CVE-2026-12310 Memory safety bug fixed in Thunderbird 152 (7.5 HIGH)