CVE-2021-4154: Use After Free
A use-after-free flaw was found in cgroup1parseparam in kernel/cgroup/cgroup-v1.c in the Linux kernel cgroup v1 parser, where a local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout and a denial of service problem on the system.
Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3b0462726e7ef281c35a7a4ae33e93ee2bc9975b
Other sources
A use-after-free flaw was found in cgroup1parseparam in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-4154.
What is the severity of CVE-2021-4154?
CVE-2021-4154 has a severity score of 8.8, which is considered high.
How does CVE-2021-4154 affect the Linux kernel's cgroup v1 parser?
CVE-2021-4154 is a use-after-free flaw in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c, which can lead to a privilege escalation, container breakout, and a denial of service attack.
Which software is affected by CVE-2021-4154?
The affected software includes Google Android, Red Hat Kernel (up to version 5.14), Red Hat Kernel-RT (up to version 4.18.0-348.20.1), and Red Hat Kernel (up to version 4.18.0-305.34.2).
How can I fix the CVE-2021-4154 vulnerability?
To fix the CVE-2021-4154 vulnerability, you should update your software to the recommended versions provided by the respective vendors.