ZeroHour

CVE-2021-4154

CVSS 3.1
8.8 high
EPSS
1%p66
Published
()
Modified
Description

A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.

Vendors
linuxredhatnetapp
Products
linux kernel, virtualization, enterprise linux, hci baseboard management controller
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news