Red Hat released kernel and live-patch updates to remediate CVE-2021-4155, a local information-disclosure flaw in the XFS filesystem. A local user could use the XFS_IOC_ALLOCSP ioctl to extend a file to an unaligned size and expose raw block-device data that should not be accessible. The issue was rated Important and was also bundled with other kernel flaws that could enable local privilege escalation or use-after-free conditions.
Affected offerings included RHEL 6 Extended Lifecycle Support, RHEL 7 Server and SAP update streams, RHEL 8.1 SAP Solutions, and RHEL 8.2 real-time telecommunications and NFV deployments, across x86_64, ppc64le, i386, and s390x where applicable. Red Hat supplied conventional kernel updates requiring a reboot, including RHEL 7 kernel 3.10.0-1062.63.1.el7, RHEL 6 ELS kernel 2.6.32-754.47.1.el6, and RHEL 8.2 real-time kernel 4.18.0-193.75.1.rt13.125.el8_2; selected RHEL 7 and RHEL 8 systems could instead apply updated kpatch modules to patch the running kernel without a conventional reboot.

See real exploitation activity before you spend the cycle.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:1417, an Important-rated kernel update for RHEL 6 Extended Lifecycle Support, including ELS Extension offerings. Kernel version 2.6.32-754.47.1.el6 fixed CVE-2021-4155 and three privilege-escalation flaws; systems required a reboot.
RHSA-2022:0958 provided an Important-rated kpatch-patch-4_18_0-147_58_1 update for RHEL 8.1 Update Services for SAP Solutions on x86_64 and ppc64le. The live patch remediated CVE-2021-4155 and six additional kernel vulnerabilities.
Red Hat issued RHSA-2022:0718, a kpatch-patch live-update module for RHEL 7.7 Update Services for SAP Solutions and related AUS and TUS offerings. The live patch fixed CVE-2021-4155 together with CVE-2020-0466 and CVE-2022-0330.
RHSA-2022:0712 delivered kernel version 3.10.0-1062.63.1.el7 for supported RHEL 7.7 AUS, TUS, and SAP Solutions channels. The Important-rated update addressed CVE-2021-4155, CVE-2020-0466, and CVE-2022-0330 and required a reboot.
Red Hat issued RHSA-2022:0590, an Important kpatch-patch live-kernel update for supported RHEL 8.2 EUS, AUS, TUS, and SAP Solutions channels on x86_64 and ppc64le. The update remediated CVE-2021-4155 along with CVE-2021-0920 and CVE-2021-4028 without requiring a reboot.
Red Hat issued RHSA-2022:0629 for RHEL 8.2 Extended Update Support real-time telecommunications deployments. The kernel-rt update fixed CVE-2021-4155 and two use-after-free vulnerabilities; affected systems required a reboot.
Red Hat issued RHSA-2022:0592, an Important kpatch-patch live-kernel update for RHEL 7 and RHEL 7 Extended Life Cycle Support. The update remediated CVE-2021-4155 alongside four other kernel vulnerabilities.
Red Hat issued RHSA-2022:0533, an Important kpatch-patch live update for supported RHEL 7.6 AUS and Update Services for SAP Solutions deployments on x86_64 and ppc64le. The update remediated CVE-2021-4155 and CVE-2020-0466 by modifying the running kernel without a conventional reboot.
Red Hat issued RHSA-2022:0531, an Important kernel security update for supported RHEL 7.6 AUS, TUS, and SAP Solutions channels. Kernel version 3.10.0-957.88.1.el7 remediated CVE-2021-4155 and CVE-2020-0466; affected systems required a reboot.
Red Hat issued RHSA-2022:0529, an Important kernel security update for RHEL Server AUS 7.3 on x86_64. Kernel version 3.10.0-514.97.1.el7 remediated CVE-2021-4155 and CVE-2020-0466; affected systems required a reboot.
Red Hat issued Important-rated RHSA-2022:0232 for RHEL 8, providing updated kpatch-patch live-kernel modules for x86_64 and ppc64le deployments. The live patch remediated CVE-2021-4155 and CVE-2022-0185 across applicable EUS, ELL, SAP, AUS, and TUS offerings without a conventional reboot.
Red Hat issued Important-rated RHSA-2022:0176 for RHEL 8 kernel-rt deployments, providing build 4.18.0-348.12.2.rt7.143.el8_5. The update remediated CVE-2021-4155 and CVE-2022-0185 for applicable Real Time, NFV, telecommunications, and ELC offerings and required a reboot.
Red Hat issued Important-rated RHSA-2022:0188 for RHEL 8, providing kernel version 4.18.0-348.12.2.el8_5 across supported architectures and channels. The update remediated CVE-2021-4155 and CVE-2022-0185 and required systems to be rebooted.
Red Hat issued Important-rated RHSA-2022:0186 for RHEL 8.4 Extended Update Support and related service channels. Kernel version 4.18.0-305.34.2.el8_4 remediated CVE-2021-4155 alongside CVE-2021-4154 and CVE-2022-0185; affected systems required a reboot.
Red Hat published an initial description of CVE-2021-4155, a local XFS information-disclosure flaw in the XFS_IOC_ALLOCSP ioctl. An unaligned file-size increase could expose filesystem data to a local user.
Red Hat Product Security DevOps closed Bugzilla record 2034813 for CVE-2021-4155, directing further product-update information to the CVE page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
15 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.