CVE-2021-4154
published 2022-02-04CVE-2021-4154: A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user…
PriorityP344high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
1.21%
64.9th percentile
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.1 < 5.4.134 | 5.4.134 |
| linux | linux_kernel | >= 5.11 < 5.12.19 | 5.12.19 |
| linux | linux_kernel | >= 5.13 < 5.13.4 | 5.13.4 |
| linux | linux_kernel | >= 5.5 < 5.10.52 | 5.10.52 |
| msrc | cm1_kernel_5.10.93.1-4_on_cbl_mariner_1.0 | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Android
CVE-2021-4154: Kernel
vendor_android·2022-06-01·CVSS 8.8
CVE-2021-4154 [HIGH] CVE-2021-4154: Kernel
Android Security Bulletin 2022-06-01
CVE: CVE-2021-4154
Severity: HIGH
Type: EoP
Component: Kernel
References: A-218836280
Upstream kernel
Microsoft
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by
vendor_msrc·2022-02-08·CVSS 8.8
CVE-2021-4154 [HIGH] CWE-416 A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October
Red Hat
kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout
vendor_redhat·2021-12-14·CVSS 8.8
CVE-2021-4154 [HIGH] CWE-416 kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout
kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
Mitigation: Mitigation for this issue is either not available
Debian
CVE-2021-4154: linux - A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v...
vendor_debian·2021·CVSS 8.8
CVE-2021-4154 [HIGH] CVE-2021-4154: linux - A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v...
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
OSV
CVE-2021-4154: In cgroup1_parse_param of cgroup-v1
osv·2022-06-01
CVE-2021-4154 CVE-2021-4154: In cgroup1_parse_param of cgroup-v1
In cgroup1_parse_param of cgroup-v1.c, there is a possible container breakout due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA
GHSA-qvm5-4fh7-hcfx: A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1
ghsa_unreviewed·2022-02-11
CVE-2021-4154 [HIGH] CWE-416 GHSA-qvm5-4fh7-hcfx: A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
OSV
CVE-2021-4154: A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1
osv·2022-02-04·CVSS 8.8
CVE-2021-4154 [HIGH] CVE-2021-4154: A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
No detection rules found.
No public exploits indexed.
arXiv
Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source ForksWith Global History Analysis
arxiv_fulltext·2026-01-28
Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source ForksWith Global History Analysis
195
195
41
4.76
2
1
100
1
3
100
51.3%
51%
8
4.1%
4%
5
2.6%
3%
5
2.6%
3%
5
2.6%
3%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
135
60
195
0.69
69
0.48
0.59
52
35
87
0.6
60
0.6
9
8
4
13
0.69
69
[Detecting One-day Vulnerabilities in Open-source Forks With Global History Analysis]Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source Forks With Global History Analysis
[Lefeuvre]Romain Lefeuvre
University of Rennes
Rennes
France
[email protected]
[Reux]Char
Crowdstrike
What is DirtyCred and how can it be mitigated?
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] What is DirtyCred and how can it be mitigated?
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
https://bugzilla.redhat.com/show_bug.cgi?id=2034514https://cloud.google.com/anthos/clusters/docs/security-bulletins#gcp-2022-002https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3b0462726e7ef281c35a7a4ae33e93ee2bc9975bhttps://security.netapp.com/advisory/ntap-20220225-0004/https://bugzilla.redhat.com/show_bug.cgi?id=2034514https://cloud.google.com/anthos/clusters/docs/security-bulletins#gcp-2022-002https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3b0462726e7ef281c35a7a4ae33e93ee2bc9975bhttps://security.netapp.com/advisory/ntap-20220225-0004/
2022-02-04
Published