Vulnerabilities > CVE-2021-4090 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 7.1 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
local
low complexity
linux
netapp
CWE-787

Summary

An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat.

Vulnerable Configurations

Part Description Count
OS
Linux
4926
OS
Netapp
8
Hardware
Netapp
8

Common Weakness Enumeration (CWE)