---
id: CVE-2021-4090
title: >-
  An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux
  kernel
summary: >-
  An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux
  kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in
  nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with
  user privilege…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-787
  - CWE-787
vendor: linux
product: linux_kernel
affected:
  - linux_kernel < 5.16
  - linux_kernel = 5.16
  - h300s_firmware
  - h500s_firmware
  - h700s_firmware
  - h300e_firmware
  - h500e_firmware
  - h700e_firmware
  - h410s_firmware
  - h410c_firmware
patched:
  - linux_kernel 5.16
published: '2022-02-18'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-4090'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2025101'
    label: secalert@redhat.com
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c0019b7db1d7ac62c711cda6b357a659d46428fe
    label: secalert@redhat.com
  - url: >-
      https://lore.kernel.org/linux-nfs/163692036074.16710.5678362976688977923.stgit%40klimt.1015granger.net/
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20220318-0010/'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2025101'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lore.kernel.org/linux-nfs/163692036074.16710.5678362976688977923.stgit%40klimt.1015granger.net/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220318-0010/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-265688.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00339
epssPercentile: 0.24538
ingestedAt: '2026-08-25T19:31:02.469Z'
---

## Overview

An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat.

## Affected

- `linux_kernel < 5.16`
- `linux_kernel = 5.16`
- `h300s_firmware`
- `h500s_firmware`
- `h700s_firmware`
- `h300e_firmware`
- `h500e_firmware`
- `h700e_firmware`
- `h410s_firmware`
- `h410c_firmware`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.16`
