PT-2021-7327 · Linux+9 · Linux Kernel+9

Published

2021-11-25

·

Updated

2023-08-14

·

CVE-2021-4002

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way a user maps some regions of memory twice using the shmget() function, which are aligned to PUD alignment with the fault of some of the memory pages. This issue could allow a local user to get unauthorized access to some data. The flaw is related to the shmget() function and the double mapping of memory regions aligned to PUD, which could enable an attacker to access confidential data and compromise its integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1988
ALT-PU-2022-1175
ALT-PU-2022-1647
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-8995
BDU:2022-05692
CESA-2022_1975
CESA-2022_1988
CVE-2021-4002
DLA-2940-1
DLA-2941-1
DSA-5096-1
LSN-0083-1
MGASA-2021-0538
MGASA-2021-0539
OESA-2021-1475
OPENSUSE-SU-2022:0056-1
OPENSUSE-SU-2022:0131-1
OPENSUSE-SU-2022:0366-1
OPENSUSE-SU-2022_0056-1
OPENSUSE-SU-2022_0131-1
OPENSUSE-SU-2022_0366-1
RHSA-2022:1975
RHSA-2022:1988
RHSA-2022_1975
RHSA-2022_1988
RLSA-2022:1975
RLSA-2022:1988
SUSE-SU-2022:0056-1
SUSE-SU-2022:0068-1
SUSE-SU-2022:0079-1
SUSE-SU-2022:0080-1
SUSE-SU-2022:0090-1
SUSE-SU-2022:0131-1
SUSE-SU-2022:0181-1
SUSE-SU-2022:0197-1
SUSE-SU-2022:0362-1
SUSE-SU-2022:0366-1
SUSE-SU-2022:0367-1
SUSE-SU-2022:0371-1
SUSE-SU-2022:0477-1
USN-5206-1
USN-5207-1
USN-5208-1
USN-5209-1
USN-5210-1
USN-5210-2
USN-5211-1
USN-5218-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu