CVE-2021-35937
Summary
| CVE | CVE-2021-35937 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-25 20:15:00 UTC |
| Updated | 2023-11-07 03:36:00 UTC |
| Description | A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| rpm.org - Releases |
MISC |
rpm.org |
|
| 1964125 – (CVE-2021-35937) CVE-2021-35937 rpm: TOCTOU race in checks for unsafe symlinks |
MISC |
bugzilla.redhat.com |
|
| www.usenix.org/legacy/event/sec05/tech/full_papers/borisov/borisov.pdf |
MISC |
www.usenix.org |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| RPM: Multiple Vulnerabilities (GLSA 202210-22) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161314 Oracle Enterprise Linux Security Update for rpm (ELSA-2024-0463)
- 161331 Oracle Enterprise Linux Security Update for rpm (ELSA-2024-0647)
- 242744 Red Hat Update for rpm (RHSA-2024:0424)
- 242754 Red Hat Update for rpm (RHSA-2024:0463)
- 242757 Red Hat Update for rpm (RHSA-2024:0435)
- 242810 Red Hat Update for rpm (RHSA-2024:0582)
- 242816 Red Hat Update for rpm (RHSA-2024:0647)
- 242842 Red Hat Update for rpm (RHSA-2024:0453)
- 357349 Amazon Linux Security Advisory for rpm : ALAS2023-2024-573
- 379634 Alibaba Cloud Linux Security Update for rpm (ALINUX3-SA-2024:0030)
- 502949 Alpine Linux Security Update for rpm
- 505818 Alpine Linux Security Update for rpm
- 672363 EulerOS Security Update for rpm (EulerOS-SA-2022-2741)
- 672374 EulerOS Security Update for rpm (EulerOS-SA-2022-2776)
- 672457 EulerOS Security Update for rpm (EulerOS-SA-2022-2829)
- 672471 EulerOS Security Update for rpm (EulerOS-SA-2022-2855)
- 710651 Gentoo Linux RPM Multiple Vulnerabilities (GLSA 202210-22)
- 903713 Common Base Linux Mariner (CBL-Mariner) Security Update for rpm (10783)
- 903811 Common Base Linux Mariner (CBL-Mariner) Security Update for rpm (10766)
- 904119 Common Base Linux Mariner (CBL-Mariner) Security Update for rpm (10766-1)
- 941549 AlmaLinux Security Update for rpm (ALSA-2024:0463)
- 941568 AlmaLinux Security Update for rpm (ALSA-2024:0647)
- 961111 Rocky Linux Security Update for rpm (RLSA-2024:0647)