Vulnerability Description
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.1, < 5.4.134 |
| Redhat | Virtualization | 4.0 |
| Redhat | Enterprise Linux | 8.0 |
| Netapp | Hci Baseboard Management Controller | h300e |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2034514Issue TrackingPatchThird Party Advisory
- https://cloud.google.com/anthos/clusters/docs/security-bulletins#gcp-2022-002Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3bMailing ListPatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20220225-0004/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2034514Issue TrackingPatchThird Party Advisory
- https://cloud.google.com/anthos/clusters/docs/security-bulletins#gcp-2022-002Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3bMailing ListPatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20220225-0004/Third Party Advisory
FAQ
What is CVE-2021-4154?
CVE-2021-4154 is a vulnerability with a CVSS score of 8.8 (HIGH). A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by...
How severe is CVE-2021-4154?
CVE-2021-4154 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-4154?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Virtualization, Redhat Enterprise Linux, Netapp Hci Baseboard Management Controller.