-------------------------------------------------------------------------
Debian LTS Advisory DLA-3930-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                         Sean Whitton
October 22, 2024                              https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : libsepol
Version        : 3.1-1+deb11u1
CVE ID         : CVE-2021-36084 CVE-2021-36085 CVE-2021-36086 CVE-2021-36087
Debian Bug     : 990526

Multiple vulnerabilities were discovered in libsepol, a set of userspace
utilities and libraries for manipulating SELinux policies.

CVE-2021-36084, CVE-2021-36085, CVE-2021-36086

    Three use-after-free problems were discovered in the CIL compiler.
    These could lead to data corruption, denial of service or possibly
    arbitrary code execution.

CVE-2021-36087

    A heap-based buffer over-read was discovered in the CIL compiler.
    This could lead to confidentiality or integrity violations, or
    crashes.

For Debian 11 bullseye, these problems have been fixed in version
3.1-1+deb11u1.

We recommend that you upgrade your libsepol packages.

For the detailed security status of libsepol please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libsepol

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-3930-1: libsepol Security Advisory Updates

October 22, 2024
Multiple vulnerabilities were discovered in libsepol, a set of userspace utilities and libraries for manipulating SELinux policies

Summary

CVE-2021-36084, CVE-2021-36085, CVE-2021-36086

Three use-after-free problems were discovered in the CIL compiler.
These could lead to data corruption, denial of service or possibly
arbitrary code execution.

CVE-2021-36087

A heap-based buffer over-read was discovered in the CIL compiler.
This could lead to confidentiality or integrity violations, or
crashes.

For Debian 11 bullseye, these problems have been fixed in version
3.1-1+deb11u1.

We recommend that you upgrade your libsepol packages.

For the detailed security status of libsepol please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libsepol

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : libsepol
Version : 3.1-1+deb11u1
CVE ID : CVE-2021-36084 CVE-2021-36085 CVE-2021-36086 CVE-2021-36087
Debian Bug : 990526

Related News