CVE-2021-3492

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/04/2021
Last modified:
21/05/2021

Description

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:lts:*:*:* 18.04 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:lts:*:*:* 18.04.1 (including) 20.04 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:-:*:*:* 20.10 (excluding)