A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them.
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2022/01/10/1 | mailing list third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=2034813 | issue tracking third party advisory |
https://access.redhat.com/security/cve/CVE-2021-4155 | third party advisory mitigation |
https://security-tracker.debian.org/tracker/CVE-2021-4155 | third party advisory |
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=983d8e60f50806f90534cc5373d0ce867e5aaf79 | mailing list patch vendor advisory |