CyberSec.Space Logo
Back to CVE Browser

CVE-2021-3492

HIGH
8.8
CVSS Severity Score
EPSS Score0.0900%
EPSS Percentile44.11th
PublishedApr 17, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.

Affected Platforms (CPE)

πŸ’»
Canonical

Ubuntu Linux

< 18.04
πŸ’»
Canonical

Ubuntu Linux

>= 18.04.1 and < 20.04
πŸ’»
Canonical

Ubuntu Linux

< 20.10

References & Advisories

Related Vulnerabilities