CVE-2021-36087: Fedoraproject Fedora
Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an optional block.
Affected products
- Fedoraproject Fedora: version 35 only
- Selinux Project Selinux: version 3.2 only
Published 2021-07-01. Last modified 2026-06-17.