8

CVE-2021-4157

An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.0 < 4.4.269
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.269
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.233
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.191
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.120
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.38
Linux ≫ Linux Kernel Version >= 5.11 < 5.11.22
Linux ≫ Linux Kernel Version >= 5.12 < 5.12.5
Fedoraproject ≫ Fedora Version 35
Netapp ≫ H300e Firmware Version -
   Netapp ≫ H300e Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500e Firmware Version -
   Netapp ≫ H500e Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700e Firmware Version -
   Netapp ≫ H700e Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.58% 0.726
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.4 4.4 10
AV:A/AC:M/Au:S/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

https://www.oracle.com/security-alerts/cpujul2022.html
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2034342
Third Party Advisory
Issue Tracking
https://lore.kernel.org/lkml/20210517140244.822185482%40linuxfoundation.org/
https://security.netapp.com/advisory/ntap-20220602-0007/
Third Party Advisory