{"id":"CVE-2021-42739","details":"The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.","modified":"2026-04-16T00:00:36.908516583Z","published":"2021-10-20T07:15:09.140Z","related":["ALSA-2022:1988","SUSE-SU-2021:14849-1","SUSE-SU-2021:3640-1","SUSE-SU-2021:3641-1","SUSE-SU-2021:3642-1","SUSE-SU-2021:3658-1","SUSE-SU-2021:3675-1","SUSE-SU-2021:3723-1","SUSE-SU-2021:3748-1","SUSE-SU-2021:3754-1","SUSE-SU-2021:3876-1","SUSE-SU-2021:3929-1","SUSE-SU-2021:3935-1","SUSE-SU-2021:3972-1","SUSE-SU-2022:0234-1","SUSE-SU-2022:0237-1","SUSE-SU-2022:0238-1","SUSE-SU-2022:0241-1","SUSE-SU-2022:0242-1","SUSE-SU-2022:0243-1","SUSE-SU-2022:0246-1","SUSE-SU-2022:0254-1","SUSE-SU-2022:0255-1","SUSE-SU-2022:0257-1","SUSE-SU-2022:0263-1","SUSE-SU-2022:0267-1","SUSE-SU-2022:0270-1","SUSE-SU-2022:0291-1","SUSE-SU-2022:0292-1","SUSE-SU-2022:0293-1","SUSE-SU-2022:0295-1","SUSE-SU-2022:0296-1","SUSE-SU-2022:0298-1","SUSE-SU-2022:0325-1","SUSE-SU-2022:0327-1","SUSE-SU-2022:0328-1","openSUSE-SU-2021:1477-1","openSUSE-SU-2021:3641-1","openSUSE-SU-2021:3675-1","openSUSE-SU-2021:3876-1"],"references":[{"type":"WEB","url":"https://lore.kernel.org/linux-media/YHaulytonFcW+lyZ%40mwanda/"},{"type":"WEB","url":"https://seclists.org/oss-sec/2021/q2/46"},{"type":"WEB","url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=35d2969ea3c7d32aee78066b1f3cf61a0d935a4e"},{"type":"ADVISORY","url":"https://www.starwindsoftware.com/security/sw-20220804-0001/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1951739"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git","events":[{"introduced":"0"},{"fixed":"35d2969ea3c7d32aee78066b1f3cf61a0d935a4e"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git","events":[{"introduced":"0"},{"fixed":"35d2969ea3c7d32aee78066b1f3cf61a0d935a4e"}]}],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"5.14.13"}]},{"events":[{"introduced":"0"},{"last_affected":"33"}]},{"events":[{"introduced":"0"},{"last_affected":"34"}]},{"events":[{"introduced":"0"},{"last_affected":"35"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"v8r12"}]},{"events":[{"introduced":"0"},{"last_affected":"v8r13-14338"}]},{"events":[{"introduced":"0"},{"last_affected":"22.1.3"}]},{"events":[{"introduced":"0"},{"last_affected":"22.1.1"}]},{"events":[{"introduced":"0"},{"last_affected":"22.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"5.14.13"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-42739.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}