CVE-2021-3996
published 2022-08-23CVE-2021-3996: A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.63%
46.3th percentile
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | util-linux | < util-linux 2.37.3-1 (bookworm) | util-linux 2.37.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| kernel | util-linux | — | — |
| kernel | util-linux | >= 0 < 2.36.1-8+deb11u1 | 2.36.1-8+deb11u1 |
| kernel | util-linux | >= 0 < 2.37.3-1 | 2.37.3-1 |
| kernel | util-linux | >= 0 < 2.37.3-1 | 2.37.3-1 |
| kernel | util-linux | >= 0 < 2.37.3-1 | 2.37.3-1 |
| kernel | util-linux | >= 2.34 < 2.37.3 | 2.37.3 |
| msrc | cm1_util-linux_2.32.1-7_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Microsoft
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unm
vendor_msrc·2022-08-09·CVSS 5.5
CVE-2021-3996 [MEDIUM] CWE-552 A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unm
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dis
Ubuntu
util-linux vulnerabilities
vendor_ubuntu·2022-02-09
CVE-2021-3995 util-linux vulnerabilities
Title: util-linux vulnerabilities
Summary: util-linux could be made to unmount FUSE filesystems belonging to other
users.
It was discovered that util-linux incorrectly handled unmounting FUSE
filesystems. A local attacker could possibly use this issue to unmount
FUSE filesystems belonging to other users.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
util-linux: Unauthorized unmount of filesystems in libmount
vendor_redhat·2022-01-24·CVSS 5.5
CVE-2021-3996 [MEDIUM] CWE-552 util-linux: Unauthorized unmount of filesystems in libmount
util-linux: Unauthorized unmount of filesystems in libmount
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a wo
Debian
CVE-2021-3996: util-linux - A logic error was found in the libmount library of util-linux in the function th...
vendor_debian·2021·CVSS 5.5
CVE-2021-3996 [MEDIUM] CVE-2021-3996: util-linux - A logic error was found in the libmount library of util-linux in the function th...
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
Scope: local
bookworm: resolved (fixed in 2.37.3-1)
bullseye: resolved (fixed in 2.36.1-8+deb11u1)
forky: resolved (fixed in 2.37.3-1)
sid: resolved (fixed in 2.37.3-1)
trixie: resolved (fixed in 2.37.3-1)
OSV
CVE-2021-3996: A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem
osv·2022-08-23·CVSS 5.5
CVE-2021-3996 [MEDIUM] CVE-2021-3996: A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.htmlhttp://seclists.org/fulldisclosure/2022/Dec/4http://www.openwall.com/lists/oss-security/2022/11/30/2https://access.redhat.com/security/cve/CVE-2021-3996https://bugzilla.redhat.com/show_bug.cgi?id=2024628https://github.com/util-linux/util-linux/commit/166e87368ae88bf31112a30e078cceae637f4cdbhttps://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.37/v2.37.3-ReleaseNoteshttps://security.gentoo.org/glsa/202401-08https://security.netapp.com/advisory/ntap-20221209-0002/https://www.openwall.com/lists/oss-security/2022/01/24/2http://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.htmlhttp://seclists.org/fulldisclosure/2022/Dec/4http://www.openwall.com/lists/oss-security/2022/11/30/2https://access.redhat.com/security/cve/CVE-2021-3996https://bugzilla.redhat.com/show_bug.cgi?id=2024628https://github.com/util-linux/util-linux/commit/166e87368ae88bf31112a30e078cceae637f4cdbhttps://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.37/v2.37.3-ReleaseNoteshttps://security.gentoo.org/glsa/202401-08https://security.netapp.com/advisory/ntap-20221209-0002/https://www.openwall.com/lists/oss-security/2022/01/24/2
2022-08-23
Published