Vulnerability Description
A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.16 |
| Debian | Debian Linux | 9.0 |
| Fedoraproject | Fedora | 35 |
| Oracle | Communications Cloud Native Core Binding Support Function | 22.1.3 |
| Oracle | Communications Cloud Native Core Network Exposure Function | 22.1.1 |
| Oracle | Communications Cloud Native Core Policy | 22.2.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2025726Issue TrackingThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=13PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a4PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00011.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing ListThird Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/11/25/1ExploitMailing ListThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2025726Issue TrackingThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=13PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a4PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00011.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlMailing ListThird Party Advisory
- https://www.debian.org/security/2022/dsa-5096Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/11/25/1ExploitMailing ListThird Party Advisory
FAQ
What is CVE-2021-4002?
CVE-2021-4002 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some...
How severe is CVE-2021-4002?
CVE-2021-4002 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-4002?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux, Fedoraproject Fedora, Oracle Communications Cloud Native Core Binding Support Function, Oracle Communications Cloud Native Core Network Exposure Function.