← Back

CVE-2021-4154

nvd nist
Published: Feb 4, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD

Description

A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.

Affected (14)

1 product
Linux Kernel
2 products
Enterprise Linux
Virtualization
1 product
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 5.1 to 5.4.134
From 5.11 to 5.12.19
From 5.13 to 5.13.4
From 5.5 to 5.10.52
Version 5.14 rc1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Version 4.0
Configuration C
7 vulnerable

References (8)

Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.