UBUNTU-CVE-2021-3492
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3492
UBUNTU-CVE-2021-3492
Summary:
Details: Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.
References: https://ubuntu.com/security/CVE-2021-3492, https://ubuntu.com/security/notices/USN-4915-1, https://ubuntu.com/security/notices/USN-4917-1, https://www.cve.org/CVERecord?id=CVE-2021-3492
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
