cbcvebase.
CVE-2021-43411
published 2021-11-07

CVE-2021-43411: An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the…

PriorityP344high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
1.23%
65.3th percentile
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianhurd< hurd 1:0.9.git20210404-9 (sid)hurd 1:0.9.git20210404-9 (sid)
gnuhurd< 0.9.20210404-90.9.20210404-9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.