### [CVE-2021-3612](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3612) ![](https://img.shields.io/static/v1?label=Product&message=kernel&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-20-%3ECWE-119&color=brighgreen) ### Description An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. ### POC #### Reference - https://lore.kernel.org/linux-input/20210620120030.1513655-1-avlarkin82@gmail.com/ - https://www.oracle.com/security-alerts/cpujul2022.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/actions-marketplace-validations/doshyt_cve-monitor - https://github.com/doshyt/cve-monitor