Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copyfromuser() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "18.04"
}
]
},
{
"events": [
{
"introduced": "18.04.1"
},
{
"fixed": "20.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "20.10"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3492.json"