An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2035652 | Issue Tracking Third Party Advisory |
https://lore.kernel.org/lkml/20211209214707.805617-1-tj%40kernel.org/T/ | |
https://security.netapp.com/advisory/ntap-20220602-0006/ | Third Party Advisory |
https://www.debian.org/security/2022/dsa-5127 | Third Party Advisory |
https://www.debian.org/security/2022/dsa-5173 | Third Party Advisory |
https://www.oracle.com/security-alerts/cpujul2022.html | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2035652 | Issue Tracking Third Party Advisory |
https://lore.kernel.org/lkml/20211209214707.805617-1-tj%40kernel.org/T/ | |
https://security.netapp.com/advisory/ntap-20220602-0006/ | Third Party Advisory |
https://www.debian.org/security/2022/dsa-5127 | Third Party Advisory |
https://www.debian.org/security/2022/dsa-5173 | Third Party Advisory |
https://www.oracle.com/security-alerts/cpujul2022.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
21 Nov 2024, 06:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2035652 - Issue Tracking, Third Party Advisory | |
References | () https://lore.kernel.org/lkml/20211209214707.805617-1-tj%40kernel.org/T/ - | |
References | () https://security.netapp.com/advisory/ntap-20220602-0006/ - Third Party Advisory | |
References | () https://www.debian.org/security/2022/dsa-5127 - Third Party Advisory | |
References | () https://www.debian.org/security/2022/dsa-5173 - Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory |
16 May 2023, 10:59
Type | Values Removed | Values Added |
---|---|---|
References | (DEBIAN) https://www.debian.org/security/2022/dsa-5127 - Third Party Advisory | |
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20220602-0006/ - Third Party Advisory | |
References | (DEBIAN) https://www.debian.org/security/2022/dsa-5173 - Third Party Advisory | |
References | (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Third Party Advisory | |
CPE | cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.1:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.2.0:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* |
25 Jul 2022, 18:18
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Jul 2022, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Jun 2022, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 May 2022, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
30 Mar 2022, 20:10
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | |
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : 7.2
v3 : 7.8 |
References | (MISC) https://lore.kernel.org/lkml/20211209214707.805617-1-tj@kernel.org/T/ - Exploit, Mailing List, Third Party Advisory | |
References | (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2035652 - Issue Tracking, Third Party Advisory |
23 Mar 2022, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-03-23 20:15
Updated : 2024-11-21 06:37
NVD link : CVE-2021-4197
Mitre link : CVE-2021-4197
CVE.ORG link : CVE-2021-4197
JSON object : View
Products Affected
netapp
- h500s
- h300s
- h410s
- h700s
- h410c_firmware
- h410c
- h410s_firmware
- h500s_firmware
- h300s_firmware
- h700s_firmware
broadcom
- brocade_fabric_operating_system_firmware
linux
- linux_kernel
debian
- debian_linux
oracle
- communications_cloud_native_core_binding_support_function
CWE
CWE-287
Improper Authentication