CVE-2021-3997

Severity
5.5MEDIUM
EPSS
0.0%
top 94.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateAug 24

Description

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDsystemd_project/systemd240250.2
Debiansystemd< 247.3-7+3
CVEListV5systemdFixed in v251-rc1

Also affects: Fedora 34, 35, Enterprise Linux 7.0, 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4p54-q58q-8mpc: A flaw was found in systemd2022-08-24
OSV
CVE-2021-3997: A flaw was found in systemd2022-08-23
CVEList
CVE-2021-3997: A flaw was found in systemd2022-08-23

📋Vendor Advisories

4
Microsoft
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.2022-08-09
Ubuntu
systemd vulnerability2022-01-13
Red Hat
systemd: Uncontrolled recursion in systemd-tmpfiles when removing files2022-01-10
Debian
CVE-2021-3997: systemd - A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may l...2021