CVE-2021-4157
Summary
| CVE | CVE-2021-4157 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-25 19:15:00 UTC |
| Updated | 2023-11-07 03:40:00 UTC |
| Description | An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-4157 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [PATCH 5.4 061/141] pNFS/flexfiles: fix incorrect size check in decode_nfs_fh() - Greg Kroah-Hartman |
MISC |
lore.kernel.org |
|
| 2034342 – (CVE-2021-4157) CVE-2021-4157 kernel: Buffer overwrite in decode_nfs_fh function |
MISC |
bugzilla.redhat.com |
|
| [PATCH 5.4 061/141] pNFS/flexfiles: fix incorrect size check in decode_nfs_fh() - Greg Kroah-Hartman |
|
lore.kernel.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159777 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-9348)
- 159825 Oracle Enterprise Linux Security Update for kernel (ELSA-2022-1988)
- 180573 Debian Security Update for linux (CVE-2021-4157)
- 240275 Red Hat Update for kernel-rt (RHSA-2022:1975)
- 240298 Red Hat Update for kernel security (RHSA-2022:1988)
- 377053 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2022:0028)
- 390261 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2022-0014)
- 671380 EulerOS Security Update for kernel (EulerOS-SA-2022-1292)
- 671436 EulerOS Security Update for kernel (EulerOS-SA-2022-1352)
- 671474 EulerOS Security Update for kernel (EulerOS-SA-2022-1429)
- 671543 EulerOS Security Update for kernel (EulerOS-SA-2022-1475)
- 671561 EulerOS Security Update for kernel (EulerOS-SA-2022-1523)
- 671703 EulerOS Security Update for kernel (EulerOS-SA-2022-1735)
- 752340 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2377-1)
- 752349 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2382-1)
- 752354 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2393-1)
- 752359 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2411-1)
- 752360 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2407-1)
- 752363 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2423-1)
- 752364 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2422-1)
- 752391 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2549-1)
- 752463 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2809-1)
- 753271 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2424-1)
- 753362 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2376-1)
- 900792 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9264)
- 901312 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9264-1)
- 906046 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9264-2)
- 940517 AlmaLinux Security Update for kernel (ALSA-2022:1988)