7.1highHigh

CVE-2021-4090

Linux Linux Kernel

An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.1 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness
CWE-787
Assigned by
secalert@redhat.com

Dates

Published
2022-02-18
Last modified
2026-08-25
Sources
NVD

Affected products

  • Linux Linux Kernel- 5.16, 5.16
  • Netapp H300s Firmwareall versions
  • Netapp H300sall versions
  • Netapp H500s Firmwareall versions
  • Netapp H500sall versions
  • Netapp H700s Firmwareall versions
  • Netapp H700sall versions
  • Netapp H300e Firmwareall versions
  • Netapp H300eall versions
  • Netapp H500e Firmwareall versions
  • Netapp H500eall versions
  • Netapp H700e Firmwareall versions

As listed in the NVD configuration data. Not a statement about your estate.

References