A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.
                
            References
                    | Link | Resource | 
|---|---|
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=13e4ad2ce8df6e058ef482a31fdd81c725b0f7ea | Patch Vendor Advisory | 
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a4a118f2eead1d6c49e00765de89878288d4b890 | Patch Vendor Advisory | 
| https://bugzilla.redhat.com/show_bug.cgi?id=2025726 | Issue Tracking Third Party Advisory | 
| https://www.openwall.com/lists/oss-security/2021/11/25/1 | Exploit Mailing List Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html | Mailing List Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html | Mailing List Third Party Advisory | 
| https://www.debian.org/security/2022/dsa-5096 | Third Party Advisory | 
| https://www.oracle.com/security-alerts/cpujul2022.html | Patch Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Configuration 3 (hide)
                                
                                
  | 
                        
Configuration 4 (hide)
                                
                                
  | 
                        
Information
                Published : 2022-03-03 14:15
Updated : 2023-02-22 09:46
NVD link : CVE-2021-4002
Mitre link : CVE-2021-4002
JSON object : View
CWE
                
                    
                        
                        CWE-401
                        
            Missing Release of Memory after Effective Lifetime
Products Affected
                oracle
- communications_cloud_native_core_network_exposure_function
 - communications_cloud_native_core_binding_support_function
 - communications_cloud_native_core_policy
 
fedoraproject
- fedora
 
linux
- linux_kernel
 
debian
- debian_linux
 


