CVE-2021-35938
published 2022-08-25CVE-2021-35938: A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user…
PriorityP431medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.49%
39.0th percentile
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.18.0+dfsg-1 (bookworm) | rpm 4.18.0+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cbl2_rpm_4.18.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_rpm_4.14.2-15_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| rpm | rpm | < 4.18.0 | 4.18.0 |
| rpm | rpm | — | — |
| rpm | rpm | >= 0 < 4.18.0+dfsg-1 | 4.18.0+dfsg-1 |
| rpm | rpm | >= 0 < 4.18.0+dfsg-1 | 4.18.0+dfsg-1 |
| rpm | rpm | >= 0 < 4.18.0+dfsg-1 | 4.18.0+dfsg-1 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original
vendor_msrc·2022-08-09·CVSS 6.7
CVE-2021-35938 [MEDIUM] CWE-59 A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Micr
Red Hat
rpm: races with chown/chmod/capabilities calls during installation
vendor_redhat·2021-06-30·CVSS 6.7
CVE-2021-35938 [MEDIUM] CWE-59 rpm: races with chown/chmod/capabilities calls during installation
rpm: races with chown/chmod/capabilities calls during installation
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threa
Debian
CVE-2021-35938: rpm - A symbolic link issue was found in rpm. It occurs when rpm sets the desired perm...
vendor_debian·2021·CVSS 6.7
CVE-2021-35938 [MEDIUM] CVE-2021-35938: rpm - A symbolic link issue was found in rpm. It occurs when rpm sets the desired perm...
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 4.18.0+dfsg-1)
bullseye: open
forky: resolved (fixed in 4.18.0+dfsg-1)
sid: resolved (fixed in 4.18.0+dfsg-1)
trixie: resolved (fixed in 4.18.0+dfsg-1)
GHSA
GHSA-83gm-5269-qr3v: A symbolic link issue was found in rpm
ghsa_unreviewed·2022-08-26
CVE-2021-35938 [HIGH] CWE-59 GHSA-83gm-5269-qr3v: A symbolic link issue was found in rpm
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
OSV
CVE-2021-35938: A symbolic link issue was found in rpm
osv·2022-08-25·CVSS 6.7
CVE-2021-35938 [MEDIUM] CVE-2021-35938: A symbolic link issue was found in rpm
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-35938https://bugzilla.redhat.com/show_bug.cgi?id=1964114https://bugzilla.suse.com/show_bug.cgi?id=1157880https://github.com/rpm-software-management/rpm/commit/25a435e90844ea98fe5eb7bef22c1aecf3a9c033https://github.com/rpm-software-management/rpm/pull/1919https://rpm.org/wiki/Releases/4.18.0https://security.gentoo.org/glsa/202210-22https://access.redhat.com/security/cve/CVE-2021-35938https://bugzilla.redhat.com/show_bug.cgi?id=1964114https://bugzilla.suse.com/show_bug.cgi?id=1157880https://github.com/rpm-software-management/rpm/commit/25a435e90844ea98fe5eb7bef22c1aecf3a9c033https://github.com/rpm-software-management/rpm/pull/1919https://rpm.org/wiki/Releases/4.18.0https://security.gentoo.org/glsa/202210-22
2022-08-25
Published