CVE-2021-43411
published 2021-11-07CVE-2021-43411: An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the…
PriorityP344high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
1.23%
65.3th percentile
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hurd | < hurd 1:0.9.git20210404-9 (sid) | hurd 1:0.9.git20210404-9 (sid) |
| gnu | hurd | < 0.9.20210404-9 | 0.9.20210404-9 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-43411: hurd - An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a...
vendor_debian·2021·CVSS 7.5
CVE-2021-43411 [HIGH] CVE-2021-43411: hurd - An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a...
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.
Scope: local
sid: resolved (fixed in 1:0.9.git20210404-9)
GHSA
GHSA-gm4g-p4jj-grph: An issue was discovered in GNU Hurd before 0
ghsa_unreviewed·2022-05-24
CVE-2021-43411 [HIGH] CWE-863 GHSA-gm4g-p4jj-grph: An issue was discovered in GNU Hurd before 0
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.gnu.org/archive/html/bug-hurd/2021-05/msg00079.htmlhttps://salsa.debian.org/hurd-team/hurd/-/blob/4d1b079411e2f40576e7b58f9b5b78f733a2beda/debian/patches/0034-proc-Use-UIDs-for-evaluating-permissions.patchhttps://www.mail-archive.com/bug-hurd%40gnu.org/msg32112.htmlhttps://lists.gnu.org/archive/html/bug-hurd/2021-05/msg00079.htmlhttps://salsa.debian.org/hurd-team/hurd/-/blob/4d1b079411e2f40576e7b58f9b5b78f733a2beda/debian/patches/0034-proc-Use-UIDs-for-evaluating-permissions.patchhttps://www.mail-archive.com/bug-hurd%40gnu.org/msg32112.html
2021-11-07
Published