QID 198331
Date Published: 2021-04-26
QID 198331: Ubuntu Security Notification for Linux kernel (OEM) vulnerabilities (USN-4915-1)
The overlayfs implementation in the linux kernel did
not properly validate the application of file system capabilities with
respect to user namespaces
The shiftfs file system in the ubuntu linux
kernel did not properly handle faults in copy_from_user() when passing
through ioctls to an underlying file system
A local attacker could use this to gain
elevated privileges
(CVE-2021-3493)
A local attacker could use
this to cause a denial of service (memory exhaustion) or execute arbitrary
code
(CVE-2021-3492)
Solution
Refer to Ubuntu advisory: USN-4915-1 for affected packages and patching details, or update with your package manager.
Vendor References
- USN-4915-1 -
usn.ubuntu.com/4915-1
CVEs related to QID 198331
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4915-1 | Ubuntu Linux |
|