CVE-2021-43395
published 2022-12-26CVE-2021-43395: An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
23.7th percentile
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| illumos | illumos | < 2022-01-18 | 2022-01-18 |
| joyent | smartos | — | — |
| omniosce | omnios | — | — |
| openindiana | openindiana | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_oracle6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6w9w-8g4v-j4m6: An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021
ghsa_unreviewed·2022-12-26
CVE-2021-43395 [MEDIUM] CWE-667 GHSA-6w9w-8g4v-j4m6: An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.
Oracle
Oracle Oracle Systems Risk Matrix: Filesystem — CVE-2021-43395
vendor_oracle·2022-01-15·CVSS 6.5
CVE-2021-43395 [MEDIUM] Oracle Oracle Systems Risk Matrix: Filesystem — CVE-2021-43395
Oracle Oracle Systems Risk Matrix: Filesystem vulnerability
CVE: CVE-2021-43395
CVSS: 6.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.tribblix.org/relnotes.htmlhttps://github.com/illumos/illumos-gate/blob/069654420de4aade43c63c43cd2896e66945fc8a/usr/src/uts/common/fs/tmpfs/tmp_vnops.chttps://github.com/illumos/illumos-gate/blob/b3403853e80914bd0aade9b5b605da4878078173/usr/src/uts/common/fs/tmpfs/tmp_dir.chttps://github.com/illumos/illumos-gate/commit/f859e7171bb5db34321e45585839c6c3200ebb90https://illumos.topicbox.com/groups/developer/T1c9e4f27f8c2f959/security-heads-up-illumos14424https://jgardner100.wordpress.com/2022/01/20/security-heads-up/https://kebe.com/blog/?p=505https://www.illumos.org/issues/14424https://www.oracle.com/security-alerts/cpujan2022.htmlhttp://www.tribblix.org/relnotes.htmlhttps://github.com/illumos/illumos-gate/blob/069654420de4aade43c63c43cd2896e66945fc8a/usr/src/uts/common/fs/tmpfs/tmp_vnops.chttps://github.com/illumos/illumos-gate/blob/b3403853e80914bd0aade9b5b605da4878078173/usr/src/uts/common/fs/tmpfs/tmp_dir.chttps://github.com/illumos/illumos-gate/commit/f859e7171bb5db34321e45585839c6c3200ebb90https://illumos.topicbox.com/groups/developer/T1c9e4f27f8c2f959/security-heads-up-illumos14424https://jgardner100.wordpress.com/2022/01/20/security-heads-up/https://kebe.com/blog/?p=505https://www.illumos.org/issues/14424https://www.oracle.com/security-alerts/cpujan2022.html
2022-12-26
Published