Local File Creation Flaw in Linux Kernel XFS File-System
CVE-2021-4037

4.4MEDIUM

What is CVE-2021-4037?

A vulnerability exists in the logic of the inode_init_owner() function within the Linux kernel, specifically affecting the handling of file ownership in the XFS file-system. It allows local users to create files with unintended group ownership and potentially elevate permissions due to SGID settings on writable directories not limited to group members. This flaw may result in unauthorized access and excessive permissions that compromise system security, echoing issues previously identified in similar vulnerabilities.

Affected Version(s)

kernel * < 5.4.241

kernel 5.5 < 5.10.146

Red Hat Enterprise Linux 8 0:4.18.0-372.9.1.rt7.166.el8

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.