Wind River Support Network

HomeDefectsLIN1021-2110
Fixed

LIN1021-2110 : Security Advisory - linux - CVE-2021-4037

Created: Dec 2, 2021    Updated: Aug 25, 2022
Resolved Date: Mar 25, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.9
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.

https://nvd.nist.gov/vuln/detail/CVE-2021-4037

CVEs


Live chat
Online