cbcvebase.
CVE-2021-35938
published 2022-08-25

CVE-2021-35938: A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user…

PriorityP431medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.49%
39.0th percentile
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianrpm< rpm 4.18.0+dfsg-1 (bookworm)rpm 4.18.0+dfsg-1 (bookworm)
fedoraprojectfedora
msrccbl2_rpm_4.18.0-1_on_cbl_mariner_2.0
msrccm1_rpm_4.14.2-15_on_cbl_mariner_1.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
rpmrpm< 4.18.04.18.0
rpmrpm
rpmrpm>= 0 < 4.18.0+dfsg-14.18.0+dfsg-1
rpmrpm>= 0 < 4.18.0+dfsg-14.18.0+dfsg-1
rpmrpm>= 0 < 4.18.0+dfsg-14.18.0+dfsg-1

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.