CVE-2021-4154
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Linux Kernel, Red Hat, Red Os, Rocky Linux
- Linux Linux Kernel
- < 5.4.134, 5.10.52, 5.12.19, 5.13.4, 5.14
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2022-02-04
CVE-2021-4154 at NVD
5 known exploits for CVE-2021-4154
Proof-of-concept code and exploit modules indexed by Sploitus