UBUNTU-CVE-2021-3995
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3995
UBUNTU-CVE-2021-3995
Summary:
Details: A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
References: https://ubuntu.com/security/CVE-2021-3995, https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.37/v2.37.3-ReleaseNotes, https://www.openwall.com/lists/oss-security/2022/01/24/2, https://ubuntu.com/security/notices/USN-5279-1, https://www.cve.org/CVERecord?id=CVE-2021-3995
Affected packages
Package
Name: util-linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
