Local File Creation Flaw in Linux Kernel XFS File-System
CVE-2021-4037
4.4MEDIUM
Key Information:
- Vendor
Linux
- Status
- Vendor
- CVE Published:
- 24 August 2022
What is CVE-2021-4037?
A vulnerability exists in the logic of the inode_init_owner() function within the Linux kernel, specifically affecting the handling of file ownership in the XFS file-system. It allows local users to create files with unintended group ownership and potentially elevate permissions due to SGID settings on writable directories not limited to group members. This flaw may result in unauthorized access and excessive permissions that compromise system security, echoing issues previously identified in similar vulnerabilities.
Affected Version(s)
kernel * < 5.4.241
kernel 5.5 < 5.10.146
Red Hat Enterprise Linux 8 0:4.18.0-372.9.1.rt7.166.el8