CVE-2021-26910Time-of-check Time-of-use (TOCTOU) Race Condition in Project Firejail

Severity
7.0HIGHNVD
CNA7.8
EPSS
0.1%
top 84.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateMay 24

Description

Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages2 packages

Debianfirejail_project/firejail< 0.9.64.4-1+3

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2q4h-h5jp-942w: Firejail before 02022-05-24
CVEList
CVE-2021-26910: Firejail before 02021-02-08
OSV
CVE-2021-26910: Firejail before 02021-02-08

📋Vendor Advisories

2
Ubuntu
Firejail vulnerability2021-11-11
Debian
CVE-2021-26910: firejail - Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions...2021
CVE-2021-26910 — Project Firejail vulnerability | cvebase