First published: Fri Nov 19 2021(Updated: )
An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, and write leading to a system integrity and confidentiality threat. Upstream discussion: <a href="https://lore.kernel.org/linux-nfs/97860.1636837122@crash.local/">https://lore.kernel.org/linux-nfs/97860.1636837122@crash.local/</a> <a href="https://lore.kernel.org/linux-nfs/163692036074.16710.5678362976688977923.stgit@klimt.1015granger.net/">https://lore.kernel.org/linux-nfs/163692036074.16710.5678362976688977923.stgit@klimt.1015granger.net/</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <5.16 | 5.16 |
Linux Kernel | <5.16 | |
Linux Kernel | =5.16 | |
Linux Kernel | =5.16-rc1 | |
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
All of | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700E | ||
NetApp H700E | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
All of | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700E | ||
NetApp H700E | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4090 is classified as a high severity vulnerability due to its potential to allow local attackers to execute out-of-bounds memory writes.
To mitigate CVE-2021-4090, update the Linux kernel to version 5.16 or later.
CVE-2021-4090 affects users of the Linux kernel versions prior to 5.16 and certain NetApp firmware.
An attacker can exploit CVE-2021-4090 to perform out-of-bounds memory writes, potentially leading to privilege escalation or data leakage.
CVE-2021-4090 specifically affects the NFS server implementation in the Linux kernel.