7.8
CVE-2021-4197
- EPSS 0.01%
- Veröffentlicht 23.03.2022 20:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:07
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.2 < 4.14.276
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.238
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.189
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.111
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.14
Oracle ≫ Communications Cloud Native Core Binding Support Function Version22.1.1
Oracle ≫ Communications Cloud Native Core Binding Support Function Version22.1.3
Oracle ≫ Communications Cloud Native Core Binding Support Function Version22.2.0
Debian ≫ Debian Linux Version10.0
Broadcom ≫ Brocade Fabric Operating System Firmware Version-
Netapp ≫ H300s Firmware Version-
Netapp ≫ H500s Firmware Version-
Netapp ≫ H700s Firmware Version-
Netapp ≫ H410s Firmware Version-
Netapp ≫ H410c Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.01% | 0.016 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.