CVE-2021-4197

An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.2.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:37

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2035652 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2035652 - Issue Tracking, Third Party Advisory
References () https://lore.kernel.org/lkml/20211209214707.805617-1-tj%40kernel.org/T/ - () https://lore.kernel.org/lkml/20211209214707.805617-1-tj%40kernel.org/T/ -
References () https://security.netapp.com/advisory/ntap-20220602-0006/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20220602-0006/ - Third Party Advisory
References () https://www.debian.org/security/2022/dsa-5127 - Third Party Advisory () https://www.debian.org/security/2022/dsa-5127 - Third Party Advisory
References () https://www.debian.org/security/2022/dsa-5173 - Third Party Advisory () https://www.debian.org/security/2022/dsa-5173 - Third Party Advisory
References () https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory () https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory

07 Nov 2023, 03:40

Type Values Removed Values Added
References
  • {'url': 'https://lore.kernel.org/lkml/20211209214707.805617-1-tj@kernel.org/T/', 'name': 'https://lore.kernel.org/lkml/20211209214707.805617-1-tj@kernel.org/T/', 'tags': ['Exploit', 'Mailing List', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://lore.kernel.org/lkml/20211209214707.805617-1-tj%40kernel.org/T/ -

Information

Published : 2022-03-23 20:15

Updated : 2024-11-21 06:37


NVD link : CVE-2021-4197

Mitre link : CVE-2021-4197

CVE.ORG link : CVE-2021-4197


JSON object : View

Products Affected

netapp

  • h700s
  • h300s
  • h300s_firmware
  • h410s_firmware
  • h410c_firmware
  • h500s
  • h410c
  • h700s_firmware
  • h410s
  • h500s_firmware

linux

  • linux_kernel

oracle

  • communications_cloud_native_core_binding_support_function

debian

  • debian_linux

broadcom

  • brocade_fabric_operating_system_firmware
CWE
CWE-287

Improper Authentication