CVE-2021-4090

Updated on 18 Feb 2022

Severity

7.1 High severity

Details

CVSS score
7.1
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Overview

About vulnerability

An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat.

Details

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Ubuntu 20.04 AWS Hirsute Released
8 kernels
  • 5.11.0-1027.30~20.04.1
  • 5.11.0-1025.27~20.04.1
  • 5.11.0-1021.22~20.04.2
  • 5.11.0-1019.20~20.04.1
  • 5.11.0-1023.24~20.04.1
  • 5.11.0-1017.18~20.04.1
  • 5.11.0-1022.23~20.04.1
  • 5.11.0-1020.21~20.04.2
Ubuntu 20.04 HWE Hirsute Released
10 kernels
  • 5.11.0-36.40~20.04.1
  • 5.11.0-43.47~20.04.2
  • 5.11.0-44.48~20.04.2
  • 5.11.0-37.41~20.04.2
  • 5.11.0-25.27~20.04.1
  • 5.11.0-38.42~20.04.1
  • 5.11.0-46.51~20.04.1
  • 5.11.0-34.36~20.04.1
  • 5.11.0-27.29~20.04.1
  • 5.11.0-40.44~20.04.2