CVE-2021-4002: Medium severity linux kernel vulnerability

Published Nov 22, 2021
·
Updated

A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.

Other sources

On Linux 3.6 and later is is possible to leak or corrupt data that resides on hugetlbs. Such data can reside on hugetlbfs, for instance, if the victim runs mmap() using the MAPHUGETLB or shmget() with SHMHUGETLB.

The bug is caused due to a missing TLB flush when unmapping of a page of PMDs is performed by clearing a PUD. While the comment in the code claims that it is safe, it is not since no flush would take place under these circumstances (unless, of course it was needed for some other reason).

Red Hat

Affected Software

14 affected componentsFixes available
redhat/kernel-rt<0:4.18.0-372.9.1.rt7.166.el8
0:4.18.0-372.9.1.rt7.166.el8
redhat/kernel<0:4.18.0-372.9.1.el8
0:4.18.0-372.9.1.el8
redhat/kernel<5.16
5.16
Linux Linux kernel<5.16
Linux Linux kernel=5.16
Linux Linux kernel=5.16-rc1
Linux Linux kernel=5.16-rc2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=35
Oracle Communications Cloud Native Core Binding Support Function=22.1.3
Oracle Communications Cloud Native Core Network Exposure Function=22.1.1
Oracle Communications Cloud Native Core Policy=22.2.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1

Remediation

Information

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Event History

Nov 25, 2021
CVE Published
12:00 AM
Mar 3, 2022
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:00 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·04:30 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:31 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-4002?

The severity of CVE-2021-4002 is categorized as medium.

2

How do I fix CVE-2021-4002?

To fix CVE-2021-4002, update the Linux kernel to version 0:4.18.0-372.9.1.rt7.166.el8 or 0:4.18.0-372.9.1.el8 or any appropriate version that addresses the vulnerability.

3

Who is affected by CVE-2021-4002?

CVE-2021-4002 affects local users on systems running vulnerable versions of the Linux kernel where hugetlbfs is utilized.

4

What is the nature of CVE-2021-4002?

CVE-2021-4002 is a memory leak vulnerability in the Linux kernel's hugetlbfs memory usage.

5

Can CVE-2021-4002 lead to unauthorized access?

Yes, CVE-2021-4002 could allow a local user to gain unauthorized access to sensitive data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203