CVE-2021-3492

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.05 % (19th)
0.05% Progress
Affected Products 1
Advisories 2

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.

Weaknesses
CWE-401
Missing Release of Memory after Effective Lifetime
CWE-415
Double Free
CVE Status
PUBLISHED
CNA
Canonical Ltd.
Published Date
2021-04-17 05:15:13
(3 years ago)
Updated Date
2021-05-21 16:08:32
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Canonical Ubuntu Linux prior 18.04 version cpe:2.3:o:canonical:ubuntu_linux::*:*:*:lts < 18.04
  Canonical Ubuntu Linux from 18.04.1 version and prior 20.04 version cpe:2.3:o:canonical:ubuntu_linux::*:*:*:lts >= 18.04.1 < 20.04

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux prior 20.10 version cpe:2.3:o:canonical:ubuntu_linux::*:*:*:- < 20.10
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...