CVE-2021-3506

Executive Summary

Out‑of‑bounds memory access in the f2fs filesystem driver (Linux kernel <5.12) allows a local attacker to read beyond allocated buffers, potentially leaking kernel data or causing a crash. The flaw can disrupt system availability but does not provide privilege escalation. No current CISA KEV listing.


Authoritative CVE Metadata - CVSS Base Score: 7.1 (HIGH) - Published: 2021-04-19T22:15:13.110 - Last Modified: 2026-09-01T18:04:20.630

Original Description: An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.

"He that never changes his opinions, never corrects his mistakes, and will never be wiser on the morrow than he is today."

— Tryon Edwards
Source: NVD