fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "8.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:communications_session_border_controller:8.2:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:communications_session_border_controller:8.3:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:communications_session_border_controller:8.4:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "9.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "9.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "34"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "3.16"
},
{
"fixed": "4.4.276"
},
{
"introduced": "4.5"
},
{
"fixed": "4.9.276"
},
{
"introduced": "4.10"
},
{
"fixed": "4.14.240"
},
{
"introduced": "4.15"
},
{
"fixed": "4.19.198"
},
{
"introduced": "4.20"
},
{
"fixed": "5.4.134"
},
{
"introduced": "5.5"
},
{
"fixed": "5.10.52"
},
{
"introduced": "5.11"
},
{
"fixed": "5.12.19"
},
{
"introduced": "5.13"
},
{
"fixed": "5.13.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "12.4.2-02044"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:sonicwall:sma1000_firmware:*:*:*:*:*:*:*:*"
}
]
}{
"extracted_events": [
{
"introduced": "3.12.43"
},
{
"fixed": "3.13"
}
],
"source": [
"CPE_FIELD",
"REFERENCES"
],
"cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-33909.json"
[
{
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2021-33909-37310894",
"digest": {
"length": 101.0,
"function_hash": "33647813340154487149123856384192856444"
},
"source": "https://github.com/torvalds/linux/commit/8cae8cd89f05f6de223d63e6d15e31c8ba9cf53b",
"target": {
"file": "fs/seq_file.c",
"function": "seq_buf_alloc"
},
"deprecated": false
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2021-33909-c0c0a02a",
"digest": {
"line_hashes": [
"74254866291374402956710747649521950744",
"80765060961419181796369186824257428641",
"30272898263732629582390626314069094611",
"249931424290703359451893110809274264261"
],
"threshold": 0.9
},
"source": "https://github.com/torvalds/linux/commit/8cae8cd89f05f6de223d63e6d15e31c8ba9cf53b",
"target": {
"file": "fs/seq_file.c"
},
"deprecated": false
}
]
"2026-04-12T03:27:56Z"