cbcvebase.
CVE-2021-4002
published 2022-03-03

CVE-2021-4002: A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are…

PriorityP418medium4.4CVSS 3.1
AVLACLPRLUINSUCLILAN
EPSS
0.52%
40.4th percentile
A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.15.5-1 (bookworm)linux 5.15.5-1 (bookworm)
fedoraprojectfedora
linuxlinux_kernel< 5.165.16
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 4.15.0-166.1744.15.0-166.174
linuxlinux_kernel>= 0 < 5.4.0-92.1035.4.0-92.103
linuxlinux_kernel>= 0 < 5.4.0-94.1065.4.0-94.106
linuxlinux_kernel>= 0 < 4.4.0-218.2514.4.0-218.251
linuxlinux_kernel>= 0 < 4.15.0-166.1744.15.0-166.174
linuxlinux_kernel>= 0 < 5.4.0-92.1035.4.0-92.103
msrccbl2_kernel_5.15.32.1-2_on_cbl_mariner_2.0
msrccm1_kernel_5.10.109.1-2_on_cbl_mariner_1.0
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_network_exposure_function
oraclecommunications_cloud_native_core_policy
paloaltopan-os

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.4MEDIUM
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.