Skip to content

kernel CVE-2021-4155

High
cbgbt published GHSA-7x2p-qg99-5mpv Jan 26, 2022

Package

kernel (bottlerocket)

Affected versions

< 1.5.3

Patched versions

1.5.3

Description

A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them.

Severity

High

CVE ID

CVE-2021-4155

Weaknesses

No CWEs