U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-4037

Change History

CVE Modified by Red Hat, Inc. 8/10/2026 1:17:27 PM

Action Type Old Value New Value
Changed Description
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not.  This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.
Added CVSS V3.1

                  
                
              
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2022:1975
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2022:1988
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2022:4829
Added Reference

                  
                
              
https://access.redhat.com/errata/RHSA-2022:4835
Removed Reference
https://bugzilla.redhat.com/show_bug.cgi?id=2004810

                  
                
              
Removed Reference
https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html

                  
                
              
Removed Reference
https://www.debian.org/security/2022/dsa-5257

                  
                
              
Removed Reference Type
https://bugzilla.redhat.com/show_bug.cgi?id=2004810 Types: Issue Tracking, Permissions Required, Third Party Advisory

                  
                
              
Removed Reference Type
https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html Types: Mailing List, Third Party Advisory

                  
                
              
Removed Reference Type
https://www.debian.org/security/2022/dsa-5257 Types: Third Party Advisory

                  
                
              
Changed Affected
[{"vendor":"n/a","product":"Kernel","versions":[{"version":"Fixed in Linux-kernel v5.11-rc1","status":"affected"}]}]
[{"vendor":"Linux","product":"kernel","defaultStatus":"unaffected","collectionURL":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/","packageName":"kernel","versions":[{"version":"*","lessThan":"5.4.241","versionType":"semver","status":"affected"},{"version":"5.5","lessThan":"5.10.146","versionType":"semver","status":"affected"},{"version":"5.12","versionType":"semver","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel-rt","cpes":["cpe:/a:redhat:enterprise_linux:8::nfv","cpe:/a:redhat:enterprise_linux:8::realtime"],"versions":[{"version":"0:4.18.0-372.9.1.rt7.166.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/a:redhat:enterprise_linux:8::crb","cpe:/o:redhat:enterprise_linux:8::baseos"],"versions":[{"version":"0:4.18.0-372.9.1.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel-rt","cpes":["cpe:/a:redhat:rhel_eus:8.4::nfv","cpe:/a:redhat:rhel_eus:8.4::realtime"],"versions":[{"version":"0:4.18.0-305.49.1.rt7.121.el8_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/a:redhat:rhel_eus:8.4::crb","cpe:/o:redhat:rhel_eus:8.4::baseos"],"versions":[{"version":"0:4.18.0-305.49.1.el8_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel-rt","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kernel","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]