PT-2021-1515 · Linux+9 · Linux Kernel+9

Published

2021-07-19

·

Updated

2025-10-17

·

CVE-2021-33909

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.16 through 5.13.x before 5.13.4
Description The issue is related to an integer overflow and out-of-bounds write in the Linux kernel's filesystem layer, specifically in the fs/seq file.c component. This can be exploited by an unprivileged user to escalate privileges to root. The vulnerability can be triggered by creating, mounting, and deleting a deep directory structure with a total path length exceeding 1GB, allowing an attacker to write to a kernel buffer. Qualys security researchers have verified the vulnerability and developed an exploit, obtaining full root privileges on default installations of several Linux distributions, including Ubuntu and Debian.
Recommendations For Linux kernel versions 3.16 through 5.13.x before 5.13.4, update to version 5.13.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable fs/seq file.c component to minimize the risk of exploitation. Avoid creating deep directory structures that could trigger the vulnerability until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:2714
ALSA-2021_2714
ALSA-2024_2394
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2021-2284
ALT-PU-2021-2288
ALT-PU-2021-2289
ALT-PU-2021-2297
ALT-PU-2021-2298
ALT-PU-2021-2312
ALT-PU-2021-2314
ALT-PU-2021-2334
ALT-PU-2021-2355
ALT-PU-2021-2363
ALT-PU-2021-2365
ALT-PU-2021-2671
ALT-PU-2021-3000
ALT-PU-2021-3002
ALT-PU-2021-3007
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-2096
ASB-A-195082750
AZL-6565
BDU:2021-03848
CESA-2021_2714
CESA-2021_2715
CESA-2021_2716
CESA-2021_2725
CVE-2021-33909
DLA-2713-1
DLA-2713-2
DLA-2714-1
DSA-4941-1
ELSA-2021-2714
ELSA-2021-2725
ELSA-2021-9368
ELSA-2021-9369
ELSA-2021-9370
ELSA-2021-9371
ELSA-2021-9372
ELSA-2021-9374
ELSA-2021-9395
ELSA-2021-9404
ELSA-2021-9406
ELSA-2021-9407
ELSA-2021-9410
LSN-0079-1
LSN-0081-1
LSN-0083-1
MGASA-2021-0366
MGASA-2021-0367
OESA-2021-1293
OPENSUSE-SU-2021:1076-1
OPENSUSE-SU-2021:2409-1
OPENSUSE-SU-2021:2415-1
OPENSUSE-SU-2021:2427-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_1076-1
OPENSUSE-SU-2021_2409-1
OPENSUSE-SU-2021_2415-1
OPENSUSE-SU-2021_2427-1
OPENSUSE-SU-2021_3876-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2021:2714
RHSA-2021:2715
RHSA-2021:2716
RHSA-2021:2718
RHSA-2021:2719
RHSA-2021:2720
RHSA-2021:2722
RHSA-2021:2723
RHSA-2021:2725
RHSA-2021:2726
RHSA-2021:2727
RHSA-2021:2728
RHSA-2021:2729
RHSA-2021:2730
RHSA-2021:2731
RHSA-2021:2732
RHSA-2021:2733
RHSA-2021:2734
RHSA-2021:2735
RHSA-2021:2736
RHSA-2021:2737
RHSA-2021_2714
RHSA-2021_2715
RHSA-2021_2725
RHSA-2021_2726
RHSA-2021_2735
RLSA-2021:2714
RLSA-2021_2714
SUSE-SU-2021:2406-1
SUSE-SU-2021:2407-1
SUSE-SU-2021:2408-1
SUSE-SU-2021:2409-1
SUSE-SU-2021:2415-1
SUSE-SU-2021:2416-1
SUSE-SU-2021:2421-1
SUSE-SU-2021:2422-1
SUSE-SU-2021:2427-1
SUSE-SU-2021:2438-1
SUSE-SU-2021:2451-1
SUSE-SU-2021:2487-1
SUSE-SU-2021:2538-1
SUSE-SU-2021:2542-1
SUSE-SU-2021:2559-1
SUSE-SU-2021:2560-1
SUSE-SU-2021:2577-1
SUSE-SU-2021:2584-1
SUSE-SU-2021:2643-1
SUSE-SU-2021:2678-1
SUSE-SU-2021:3876-1
SUSE-SU-2021_2406-1
SUSE-SU-2021_2407-1
SUSE-SU-2021_2408-1
SUSE-SU-2021_2409-1
SUSE-SU-2021_2415-1
SUSE-SU-2021_2416-1
SUSE-SU-2021_2421-1
SUSE-SU-2021_2422-1
SUSE-SU-2021_2427-1
SUSE-SU-2021_2438-1
SUSE-SU-2021_2451-1
SUSE-SU-2021_2487-1
SUSE-SU-2021_2538-1
SUSE-SU-2021_2542-1
SUSE-SU-2021_2559-1
SUSE-SU-2021_2560-1
SUSE-SU-2021_2577-1
SUSE-SU-2021_2584-1
SUSE-SU-2021_2678-1
USN-5014-1
USN-5015-1
USN-5016-1
USN-5017-1
USN-5018-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu