CyberSec.Space Logo
返回 CVE 浏览器

CVE-2021-3492

HIGH
8.8
CVSS Severity Score
EPSS Score0.0900%
EPSS Percentile44.11th
Published2021年4月17日
Last Modified2024年11月21日

Vulnerability Description

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.

Affected Platforms (CPE)

💻
Canonical

Ubuntu Linux

< 18.04
💻
Canonical

Ubuntu Linux

>= 18.04.1 and < 20.04
💻
Canonical

Ubuntu Linux

< 20.10

References & Advisories

相关漏洞威胁