2021-11-22 08:00:57 +00:00
{
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"data_version" : "4.0" ,
"CVE_data_meta" : {
"ID" : "CVE-2021-3996" ,
2022-08-23 20:00:43 +00:00
"ASSIGNER" : "secalert@redhat.com" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "n/a" ,
"product" : {
"product_data" : [
{
"product_name" : "util-linux" ,
"version" : {
"version_data" : [
{
"version_value" : "Fixed in util-linux v2.37.3"
}
]
}
}
]
}
}
]
}
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-552 - Files or Directories Accessible to External Parties"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"refsource" : "MISC" ,
"name" : "https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.37/v2.37.3-ReleaseNotes" ,
"url" : "https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.37/v2.37.3-ReleaseNotes"
} ,
{
"refsource" : "MISC" ,
"name" : "https://github.com/util-linux/util-linux/commit/166e87368ae88bf31112a30e078cceae637f4cdb" ,
"url" : "https://github.com/util-linux/util-linux/commit/166e87368ae88bf31112a30e078cceae637f4cdb"
} ,
{
"refsource" : "MISC" ,
"name" : "https://www.openwall.com/lists/oss-security/2022/01/24/2" ,
"url" : "https://www.openwall.com/lists/oss-security/2022/01/24/2"
} ,
{
"refsource" : "MISC" ,
"name" : "https://bugzilla.redhat.com/show_bug.cgi?id=2024628" ,
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2024628"
} ,
{
"refsource" : "MISC" ,
"name" : "https://access.redhat.com/security/cve/CVE-2021-3996" ,
"url" : "https://access.redhat.com/security/cve/CVE-2021-3996"
2022-12-01 01:00:33 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[oss-security] 20221130 Race condition in snap-confine's must_mkdir_and_open_with_perms() (CVE-2022-3328)" ,
"url" : "http://www.openwall.com/lists/oss-security/2022/11/30/2"
2022-12-09 05:00:35 +00:00
} ,
{
"refsource" : "FULLDISC" ,
"name" : "20221208 Race condition in snap-confine's must_mkdir_and_open_with_perms() (CVE-2022-3328)" ,
"url" : "http://seclists.org/fulldisclosure/2022/Dec/4"
2022-12-09 17:00:37 +00:00
} ,
{
"refsource" : "MISC" ,
"name" : "http://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.html" ,
"url" : "http://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.html"
2022-12-09 19:00:38 +00:00
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://security.netapp.com/advisory/ntap-20221209-0002/" ,
"url" : "https://security.netapp.com/advisory/ntap-20221209-0002/"
2024-01-07 10:00:36 +00:00
} ,
{
"refsource" : "GENTOO" ,
"name" : "GLSA-202401-08" ,
"url" : "https://security.gentoo.org/glsa/202401-08"
2022-08-23 20:00:43 +00:00
}
]
2021-11-22 08:00:57 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2022-08-23 20:00:43 +00:00
"value" : "A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems."
2021-11-22 08:00:57 +00:00
}
]
}
}