CVE-2021-4157
Vulnerability Summary
Timeline
Description
An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system.
CVSS Metrics
- v3.1•HIGH•Score: 8CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.4AV:A/AC:M/Au:S/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.06%• Percentile: 17%
Techniques & Countermeasures
- CWE-119•Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Affected Systems
- fedoraproject•fedora
35
- linux•linux_kernel
≥ 4.0, < 4.4.269 | ≥ 4.5, < 4.9.269 | ≥ 4.10, < 4.14.233 | ≥ 4.15, < 4.19.191 | ≥ 4.20, < 5.4.120 | ≥ 5.5, < 5.10.38 | ≥ 5.11, < 5.11.22 | ≥ 5.12, < 5.12.5
- netapp•h300e
na
- netapp•h300s_firmware
na
- netapp•h410s_firmware
na
- netapp•h500e
na
- netapp•h500s_firmware
na
- netapp•h700e
na
- netapp•h700s_firmware
na
- oracle•communications_cloud_native_core_binding_support_function
22.1.1 | 22.1.3 | 22.2.0