PT-2021-4252 · Linux+3 · Linux Kernel+4

Vdehors

+1

·

Published

2021-04-09

·

Updated

2025-09-29

·

CVE-2021-3492

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shiftfs versions prior to the fixed version
Description The issue is related to the copy from user() function in the shiftfs file system of the Linux kernel, which is associated with a double-free memory error. This can allow an attacker to access confidential data, compromise data integrity, and cause a denial of service. The vulnerability can also be exploited to gain privileges via executing arbitrary code. An attacker could use this to cause kernel memory exhaustion.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2021-04860
CVE-2021-3492
LSN-0077-1
USN-4915-1
USN-4917-1
ZDI-21-422

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu
Shiftfs