CVE-2021-3492Missing Release of Memory after Effective Lifetime in Linux Kernel

Severity
7.8HIGHNVD
CNA8.8
EPSS
24.4%
top 3.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 24

Description

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5ubuntu/linux_kernel5.8 kernel5.8.0-50.56+1
NVDcanonical/ubuntu_linux18.04.120.04+2
Ubuntulinux/linux_kernel< 5.4.0-72.80+1

Patches

🔴Vulnerability Details

5
GHSA
GHSA-hr5j-7qj8-mpp3: Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correc2022-05-24
OSV
Kernel Live Patch Security Notice2021-05-17
CVEList
Ubuntu linux kernel shiftfs file system double free vulnerability2021-04-17
OSV
CVE-2021-3492: Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correc2021-04-15
OSV
linux-oem-5.6 vulnerabilities2021-04-15

📋Vendor Advisories

5
Ubuntu
Kernel Live Patch Security Notice2021-05-17
Red Hat
kernel: shiftfs file system double free vulnerability2021-04-16
Ubuntu
Linux kernel (OEM) vulnerabilities2021-04-15
Ubuntu
Linux kernel vulnerabilities2021-04-15
Debian
CVE-2021-3492: linux - Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, d...2021
CVE-2021-3492 — Ubuntu Linux Kernel vulnerability | cvebase