Out-of-bounds write in Linux kernel - CVE-2021-4090
Published: February 18, 2022 / Updated: December 13, 2022
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to read and manipulate data.
An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat.