{"id":"DEBIAN-CVE-2021-47636","details":"In the Linux kernel, the following vulnerability has been resolved:  ubifs: Fix read out-of-bounds in ubifs_wbuf_write_nolock()  Function ubifs_wbuf_write_nolock() may access buf out of bounds in following process:  ubifs_wbuf_write_nolock():   aligned_len = ALIGN(len, 8);   // Assume len = 4089, aligned_len = 4096   if (aligned_len \u003c= wbuf-\u003eavail) ... // Not satisfy   if (wbuf-\u003eused) {     ubifs_leb_write()  // Fill some data in avail wbuf     len -= wbuf-\u003eavail;   // len is still not 8-bytes aligned     aligned_len -= wbuf-\u003eavail;   }   n = aligned_len \u003e\u003e c-\u003emax_write_shift;   if (n) {     n \u003c\u003c= c-\u003emax_write_shift;     err = ubifs_leb_write(c, wbuf-\u003elnum, buf + written,                           wbuf-\u003eoffs, n);     // n \u003e len, read out of bounds less than 8(n-len) bytes   }  , which can be catched by KASAN:   =========================================================   BUG: KASAN: slab-out-of-bounds in ecc_sw_hamming_calculate+0x1dc/0x7d0   Read of size 4 at addr ffff888105594ff8 by task kworker/u8:4/128   Workqueue: writeback wb_workfn (flush-ubifs_0_0)   Call Trace:     kasan_report.cold+0x81/0x165     nand_write_page_swecc+0xa9/0x160     ubifs_leb_write+0xf2/0x1b0 [ubifs]     ubifs_wbuf_write_nolock+0x421/0x12c0 [ubifs]     write_head+0xdc/0x1c0 [ubifs]     ubifs_jnl_write_inode+0x627/0x960 [ubifs]     wb_workfn+0x8af/0xb80  Function ubifs_wbuf_write_nolock() accepts that parameter 'len' is not 8 bytes aligned, the 'len' represents the true length of buf (which is allocated in 'ubifs_jnl_xxx', eg. ubifs_jnl_write_inode), so ubifs_wbuf_write_nolock() must handle the length read from 'buf' carefully to write leb safely.  Fetch a reproducer in [Link].","modified":"2026-09-01T20:04:38.434081454Z","published":"2025-02-26T06:37:05.377Z","upstream":["CVE-2021-47636"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47636"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47636.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47636.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47636.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}