First published: Sun Sep 12 2021(Updated: )
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-372.9.1.rt7.166.el8 | 0:4.18.0-372.9.1.rt7.166.el8 |
redhat/kernel | <0:4.18.0-372.9.1.el8 | 0:4.18.0-372.9.1.el8 |
redhat/kernel-rt | <0:4.18.0-305.57.1.rt7.129.el8_4 | 0:4.18.0-305.57.1.rt7.129.el8_4 |
redhat/kernel | <0:4.18.0-305.57.1.el8_4 | 0:4.18.0-305.57.1.el8_4 |
redhat/Linux kernel | <5.17 | 5.17 |
Linux Linux kernel | >=4.2<4.14.276 | |
Linux Linux kernel | >=4.15<4.19.238 | |
Linux Linux kernel | >=4.20<5.4.189 | |
Linux Linux kernel | >=5.5<5.10.111 | |
Linux Linux kernel | >=5.11<5.15.14 | |
Oracle Communications Cloud Native Core Binding Support Function | =22.1.1 | |
Oracle Communications Cloud Native Core Binding Support Function | =22.1.3 | |
Oracle Communications Cloud Native Core Binding Support Function | =22.2.0 | |
Debian Debian Linux | =10.0 | |
Broadcom Brocade Fabric Operating System Firmware | ||
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
All of | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
ubuntu/linux | <4.15.0-189.200 | 4.15.0-189.200 |
ubuntu/linux | <5.4.0-117.132 | 5.4.0-117.132 |
ubuntu/linux | <5.13.0-37.42 | 5.13.0-37.42 |
ubuntu/linux | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux | <4.4.0-229.263 | 4.4.0-229.263 |
ubuntu/linux-aws | <4.15.0-1137.148 | 4.15.0-1137.148 |
ubuntu/linux-aws | <5.4.0-1078.84 | 5.4.0-1078.84 |
ubuntu/linux-aws | <5.13.0-1019.21 | 5.13.0-1019.21 |
ubuntu/linux-aws | <4.4.0-1109.115 | 4.4.0-1109.115 |
ubuntu/linux-aws | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws | <4.4.0-1145.160 | 4.4.0-1145.160 |
ubuntu/linux-aws-5.0 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-5.11 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-5.13 | <5.13.0-1019.21~20.04.1 | 5.13.0-1019.21~20.04.1 |
ubuntu/linux-aws-5.13 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-5.3 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-5.4 | <5.4.0-1078.84~18.04.1 | 5.4.0-1078.84~18.04.1 |
ubuntu/linux-aws-5.4 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-5.8 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-fips | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-hwe | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-aws-hwe | <4.15.0-1137.148~16.04.1 | 4.15.0-1137.148~16.04.1 |
ubuntu/linux-azure | <5.4.0-1083.87 | 5.4.0-1083.87 |
ubuntu/linux-azure | <5.13.0-1021.24 | 5.13.0-1021.24 |
ubuntu/linux-azure | <4.15.0-1146.161~14.04.1 | 4.15.0-1146.161~14.04.1 |
ubuntu/linux-azure | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure | <4.15.0-1146.161~16.04.1 | 4.15.0-1146.161~16.04.1 |
ubuntu/linux-azure-4.15 | <4.15.0-1146.161 | 4.15.0-1146.161 |
ubuntu/linux-azure-4.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-5.11 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-5.13 | <5.13.0-1021.24~20.04.1 | 5.13.0-1021.24~20.04.1 |
ubuntu/linux-azure-5.13 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-5.3 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-5.4 | <5.4.0-1083.87~18.04.1 | 5.4.0-1083.87~18.04.1 |
ubuntu/linux-azure-5.4 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-edge | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-fde | <5.4.0-1083.87 | 5.4.0-1083.87 |
ubuntu/linux-azure-fde | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-fde-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-azure-fips | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-bluefield | <5.4.0-1040.44 | 5.4.0-1040.44 |
ubuntu/linux-bluefield | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-dell300x | <4.15.0-1049.54 | 4.15.0-1049.54 |
ubuntu/linux-dell300x | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-fips | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp | <5.4.0-1078.84 | 5.4.0-1078.84 |
ubuntu/linux-gcp | <5.13.0-1021.25 | 5.13.0-1021.25 |
ubuntu/linux-gcp | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp | <4.15.0-1131.147~16.04.1 | 4.15.0-1131.147~16.04.1 |
ubuntu/linux-gcp-4.15 | <4.15.0-1131.147 | 4.15.0-1131.147 |
ubuntu/linux-gcp-4.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp-5.11 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp-5.13 | <5.13.0-1021.25~20.04.1 | 5.13.0-1021.25~20.04.1 |
ubuntu/linux-gcp-5.13 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp-5.3 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp-5.4 | <5.4.0-1078.84~18.04.1 | 5.4.0-1078.84~18.04.1 |
ubuntu/linux-gcp-5.8 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gcp-fips | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gke | <5.4.0-1074.79 | 5.4.0-1074.79 |
ubuntu/linux-gke | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gke-4.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gke-5.0 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gke-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gke-5.3 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gke-5.4 | <5.4.0-1074.79~18.04.1 | 5.4.0-1074.79~18.04.1 |
ubuntu/linux-gke-5.4 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gkeop | <5.4.0-1046.48 | 5.4.0-1046.48 |
ubuntu/linux-gkeop | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gkeop-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-gkeop-5.4 | <5.4.0-1046.48~18.04.1 | 5.4.0-1046.48~18.04.1 |
ubuntu/linux-gkeop-5.4 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-hwe | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-hwe | <4.15.0-189.200~16.04.1 | 4.15.0-189.200~16.04.1 |
ubuntu/linux-hwe-5.11 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-hwe-5.13 | <5.13.0-37.42~20.04.1 | 5.13.0-37.42~20.04.1 |
ubuntu/linux-hwe-5.13 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-hwe-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-hwe-5.4 | <5.4.0-117.132~18.04.1 | 5.4.0-117.132~18.04.1 |
ubuntu/linux-hwe-5.4 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-hwe-5.8 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-hwe-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-hwe-edge | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-ibm | <5.4.0-1026.29 | 5.4.0-1026.29 |
ubuntu/linux-ibm | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-ibm-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-ibm-5.4 | <5.4.0-1028.32~18.04.1 | 5.4.0-1028.32~18.04.1 |
ubuntu/linux-ibm-5.4 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-intel | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-intel-5.13 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-intel-iotg | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-intel-iotg-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-iot | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-kvm | <4.15.0-1123.128 | 4.15.0-1123.128 |
ubuntu/linux-kvm | <5.4.0-1068.72 | 5.4.0-1068.72 |
ubuntu/linux-kvm | <5.13.0-1018.19 | 5.13.0-1018.19 |
ubuntu/linux-kvm | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-kvm | <4.4.0-1110.120 | 4.4.0-1110.120 |
ubuntu/linux-laptop | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-lowlatency | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-lowlatency-hwe-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-lowlatency-hwe-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-lts-xenial | <4.4.0-229.263~14.04.1 | 4.4.0-229.263~14.04.1 |
ubuntu/linux-lts-xenial | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-nvidia | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-nvidia-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-nvidia-6.8 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-nvidia-lowlatency | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-5.10 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-5.13 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-5.14 | <5.14.0-1022.24 | 5.14.0-1022.24 |
ubuntu/linux-oem-5.17 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-5.6 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-6.0 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-6.1 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-6.8 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oem-osp1 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oracle | <4.15.0-1102.113 | 4.15.0-1102.113 |
ubuntu/linux-oracle | <5.4.0-1076.83 | 5.4.0-1076.83 |
ubuntu/linux-oracle | <5.13.0-1023.28 | 5.13.0-1023.28 |
ubuntu/linux-oracle | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oracle | <4.15.0-1102.113~16.04.1 | 4.15.0-1102.113~16.04.1 |
ubuntu/linux-oracle-5.0 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oracle-5.11 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oracle-5.13 | <5.13.0-1025.30~20.04.1 | 5.13.0-1025.30~20.04.1 |
ubuntu/linux-oracle-5.13 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oracle-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oracle-5.3 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-oracle-5.4 | <5.4.0-1076.83~18.04.1 | 5.4.0-1076.83~18.04.1 |
ubuntu/linux-oracle-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-raspi | <5.4.0-1065.75 | 5.4.0-1065.75 |
ubuntu/linux-raspi | <5.13.0-1022.24 | 5.13.0-1022.24 |
ubuntu/linux-raspi | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-raspi-5.4 | <5.4.0-1065.75~18.04.1 | 5.4.0-1065.75~18.04.1 |
ubuntu/linux-raspi-5.4 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-raspi2 | <4.15.0-1115.123 | 4.15.0-1115.123 |
ubuntu/linux-raspi2 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-raspi2-5.3 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-riscv | <5.13.0-1017.19 | 5.13.0-1017.19 |
ubuntu/linux-riscv | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-riscv-5.11 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-riscv-5.15 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-riscv-5.8 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-riscv-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-snapdragon | <4.15.0-1133.143 | 4.15.0-1133.143 |
ubuntu/linux-snapdragon | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-starfive | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-starfive-6.5 | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
ubuntu/linux-xilinx-zynqmp | <5.16<5.4.189<5.15.14 | 5.16 5.4.189 5.15.14 |
debian/linux | 5.10.218-1 5.10.221-1 6.1.94-1 6.1.99-1 6.9.12-1 6.10.3-1 |
The mitigation not known. However, for the default configuration of the Red Hat Enterprise Linux it is not possible to trigger this vulnerability: if control groups (cgroups) not being used or being used with the default configuration or being used some other configuration where for example similar privileges for all processes (both for parent and for child processes), then no way to trigger this vulnerability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)