A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. | A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. |
| Title | kernel: security regression for CVE-2018-13405 | Kernel: security regression for cve-2018-13405 |
| CPEs | cpe:/a:redhat:enterprise_linux:8::crb cpe:/a:redhat:enterprise_linux:8::realtime cpe:/a:redhat:rhel_eus:8.4::crb cpe:/a:redhat:rhel_eus:8.4::realtime cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8::baseos cpe:/o:redhat:enterprise_linux:9 cpe:/o:redhat:rhel_eus:8.4::baseos |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2022-08-24T00:00:00.000Z
Updated: 2026-08-10T16:47:24.930Z
Reserved: 2021-12-01T00:00:00.000Z
Link: CVE-2021-4037
No data.
Status : Modified
Published: 2022-08-24T16:15:09.257
Modified: 2026-08-10T17:17:27.980
Link: CVE-2021-4037