Linux · Linux Kernel · CVE-2021-3492
**Name of the Vulnerable Software and Affected Versions**
Shiftfs versions prior to the fixed version
**Description**
The issue is related to the `copy from user()` function in the shiftfs file system of the Linux kernel, which is associated with a double-free memory error. This can allow an attacker to access confidential data, compromise data integrity, and cause a denial of service. The vulnerability can also be exploited to gain privileges via executing arbitrary code. An attacker could use this to cause kernel memory exhaustion.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.