CVE-2021-41073

Related Vulnerabilities: CVE-2021-41073  

A flaw was found in loop_rw_iter in fs/io_uring.c in the Linux kernel. This problem gives the ability to a local user with a normal user privilege to free a user-defined kernel space buffer.

Description

A flaw was found in loop_rw_iter in fs/io_uring.c in the Linux kernel. This problem gives the ability to a local user with a normal user privilege to free a user-defined kernel space buffer.

Statement

There was no shipped kernel version that was seen affected by this problem. These files are not built in our source code.

There was no shipped kernel version that was seen affected by this problem. These files are not built in our source code.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Additional Information

  • Bugzilla 2007567: CVE-2021-41073 kernel: local user privilege escalation via loop_rw_iter in fs/io_uring.c
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • FAQ: Frequently asked questions about CVE-2021-41073