Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-4154

28
FAUCET Score

CVE-2021-4154 describes a use-after-free vulnerability in the Linux kernel's cgroup v1 parser, specifically affecting Linux, NetApp, and Red Hat products. This high-severity flaw (CVSS 8.8) allows a local attacker with user privileges to achieve privilege escalation, potentially leading to container breakout and denial of service due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including an article about Google's increased rewards for Linux kernel zero-days.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.1, < 5.4.134CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.52CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.12.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.13, < 5.13.4CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
5.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:5.14:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.0
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.21%
Probability of exploitation in next 30 days
EPSS Percentile
65.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0121 is in the 94th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

boschpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 18790-16820Fixed in: -
microsoftpatch availablevia msrc
Product: cm1 kernel 5.10.93.1-4 on CBL Mariner 1.0Fixed in: -
mongodbpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-rt-0:4.18.0-305.34.2.rt7.107.el8_4
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.4.10-202203101736_8.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-0:4.18.0-305.34.2.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-348.20.1.rt7.150.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-348.20.1.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kpatch-patch
View patch

Vendor Advisories (4)

microsoft2022-Feb/CVE-2021-4154Important

A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.

Feb 8, 2022
boschllm-bosch-9c2515a53d286b3cHIGH

Multiple Linux kernel vulnerabilities (CVE-2021-4154, CVE-2021-22600, CVE-2022-0185)

Feb 4, 2022
mongodbllm-mongodb-f0d9b58df6219bd3HIGH

Multiple Linux kernel vulnerabilities (CVE-2021-4154, CVE-2021-22600, CVE-2022-0185)

Feb 2, 2022
redhatCVE-2021-4154Important

kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout

Dec 14, 2021

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
cloud.google.com / anthos/clusters/docs/security-bulletins
Third Party Advisory
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
Mailing ListPatchVendor Advisory
security.netapp.com / advisory/ntap-20220225-0004
Third Party Advisory