CVE-2021-4037
Summary
| CVE | CVE-2021-4037 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-24 16:15:00 UTC |
| Updated | 2022-12-08 03:40:00 UTC |
| Description | A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159825 Oracle Enterprise Linux Security Update for kernel (ELSA-2022-1988)
- 181145 Debian Security Update for linux (DSA 5257-1)
- 181190 Debian Security Update for linux-5.10 (DLA 3173-1)
- 183412 Debian Security Update for linux (CVE-2021-4037)
- 240275 Red Hat Update for kernel-rt (RHSA-2022:1975)
- 240298 Red Hat Update for kernel security (RHSA-2022:1988)
- 240390 Red Hat Update for kernel-rt (RHSA-2022:4835)
- 240392 Red Hat Update for kernel security (RHSA-2022:4829)
- 257226 CentOS Security Update for kernel (CESA-2023:1091)
- 354101 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-021
- 377741 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0175)
- 377766 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2022:0049)
- 377871 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0001)
- 377891 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0002)
- 6140127 AWS Bottlerocket Security Update for kernel (GHSA-g3v4-8q9p-hjcc)
- 671367 EulerOS Security Update for kernel (EulerOS-SA-2022-1308)
- 671380 EulerOS Security Update for kernel (EulerOS-SA-2022-1292)
- 671436 EulerOS Security Update for kernel (EulerOS-SA-2022-1352)
- 671498 EulerOS Security Update for kernel (EulerOS-SA-2022-1466)
- 671543 EulerOS Security Update for kernel (EulerOS-SA-2022-1475)
- 671561 EulerOS Security Update for kernel (EulerOS-SA-2022-1523)
- 671703 EulerOS Security Update for kernel (EulerOS-SA-2022-1735)
- 752594 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3293-1)
- 752813 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3930-1)
- 752839 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3929-1)
- 752880 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4053-1)
- 752889 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3897-1)
- 752944 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4273-1)
- 752959 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4272-1)
- 753038 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4573-1)
- 753039 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4574-1)
- 753051 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4589-1)
- 753060 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4615-1)
- 753063 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4617-1)
- 753167 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3288-1)
- 903723 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10702)
- 904621 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10702-1)
- 906178 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10702-2)
- 940517 AlmaLinux Security Update for kernel (ALSA-2022:1988)