CVE-2021-36087: Fedoraproject Fedora

Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an optional block.

Affected products

Published 2021-07-01. Last modified 2026-06-17.