CVE-2021-43395Improper Locking in Illumos

CWE-667Improper Locking4 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 80.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26

Description

An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDoracle/solaris10, 11+1
NVDillumos/illumos< 2022-01-18
NVDjoyent/smartos20210923
NVDomniosce/omniosr151038
NVDopenindiana/openindianahipster_2021.04

Patches

🔴Vulnerability Details

2
CVEList
CVE-2021-43395: An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 20212022-12-26
GHSA
GHSA-6w9w-8g4v-j4m6: An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 20212022-12-26

📋Vendor Advisories

1
Oracle
Oracle Oracle Systems Risk Matrix: Filesystem — CVE-2021-433952022-01-15
CVE-2021-43395 — Improper Locking in Illumos | cvebase