VYPR
High severity8.8NVD Advisory· Published Apr 17, 2021· Updated Jun 17, 2026

CVE-2021-3492

CVE-2021-3492

Description

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:-:*:*:*range: <20.10
    • cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:lts:*:*:*range: <18.04
  • Ubuntu/Shiftfsllm-create
  • Range: 5.8 kernel

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.