CVE-2021-3732
Summary
| CVE | CVE-2021-3732 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:42:00 UTC |
| Updated | 2022-12-13 19:50:00 UTC |
| Description | A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | 5.14 | - | All | All |
| Operating System | Linux | Linux Kernel | 5.14 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 5.14 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 5.14 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 5.14 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 5.14 | rc5 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | |
| 1995249 – (CVE-2021-3732) CVE-2021-3732 kernel: overlayfs: Mounting overlayfs inside an unprivileged user namespace can reveal files | MISC | bugzilla.redhat.com | |
| CVE-2021-3732 | Ubuntu | MISC | ubuntu.com | |
| ovl: prevent private clone if bind mount is not allowed · torvalds/linux@427215d · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159492 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-4356)
- 159568 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9577)
- 178809 Debian Security Update for linux (DSA 4978-1)
- 178844 Debian Security Update for linux-4.19 (DLA 2785-1)
- 178943 Debian Security Update for linux (DLA 2843-1)
- 179727 Debian Security Update for linux (CVE-2021-3732)
- 198518 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-5094-2)
- 198520 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5094-1)
- 198524 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5096-1)
- 198540 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5113-1)
- 198542 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5115-1)
- 198544 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5116-1)
- 198546 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5116-2)
- 199560 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6001-1)
- 199568 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6013-1)
- 199577 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6014-1)
- 239816 Red Hat Update for kernel security (RHSA-2021:4356)
- 239879 Red Hat Update for kernel-rt (RHSA-2021:4140)
- 352839 Amazon Linux Security Advisory for kernel: ALAS2-2021-1704
- 352871 Amazon Linux Security Advisory for kernel : ALAS-2021-1539
- 356186 Amazon Linux Security Advisory for microvm-kernel : ALASMICROVM-KERNEL-4.14-2023-003
- 356218 Amazon Linux Security Advisory for microvm-kernel : ALASMICROVM-KERNEL-4.14-2023-002
- 390252 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2021-0039)
- 751137 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:1271-1)
- 751155 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3192-1)
- 751160 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3179-1)
- 751163 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3206-1)
- 751170 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3205-1)
- 751437 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3876-1)
- 751441 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:3876-1)
- 751451 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3935-1)
- 751473 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3969-1)
- 751476 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3972-1)
- 900772 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8935)
- 906060 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8935-1)
- 940265 AlmaLinux Security Update for kernel (ALSA-2021:4356)