Skip to content

kernel CVE-2021-33909

High
tjkirch published GHSA-73f7-3962-2mrj Jul 23, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.1.4

Patched versions

1.1.4

Description

An out-of-bounds write flaw was found in the Linux kernel's seq_file in the filesystem layer. An unprivileged local attacker can exploit this vulnerability by creating, mounting, and deleting a deep directory structure whose total path length exceeds 1GB. A successful attack results in privilege escalation.

Severity

High

CVE ID

CVE-2021-33909

Weaknesses

No CWEs