ZeroHour

CVE-2021-4002

PoC
CVSS 3.1
4.4 medium
EPSS
<1%p42
Published
()
Modified
Description

A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.

Vendors
linuxdebianfedoraprojectoracle
Products
linux kernel, debian linux, fedora, communications cloud native core binding support function, communications cloud native core network exposure function, communications cloud native core policy
Weakness
CWE-459, CWE-401
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.