cbcvebase.
CVE-2021-4197
published 2022-03-23

CVE-2021-4197: An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.54%
42.4th percentile
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 4.15.0-189.2004.15.0-189.200
linuxlinux_kernel>= 0 < 5.4.0-117.1325.4.0-117.132
linuxlinux_kernel>= 0 < 4.4.0-229.2634.4.0-229.263
linuxlinux_kernel>= 4.15 < 4.19.2384.19.238
linuxlinux_kernel>= 4.2 < 4.14.2764.14.276
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.145.15.14
linuxlinux_kernel>= 5.5 < 5.10.1115.10.111
msrccbl2_kernel_5.15.37.1-2_on_cbl_mariner_2.0
msrccm1_kernel_5.10.116.1-1_on_cbl_mariner_1.0
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_binding_support_function

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.