{"api_version":"1","generated_at":"2026-07-23T23:41:51+00:00","cve":"CVE-2021-40153","urls":{"html":"https://cve.report/CVE-2021-40153","api":"https://cve.report/api/cve/CVE-2021-40153.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-40153","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-40153"},"summary":{"title":"CVE-2021-40153","description":"squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-08-27 15:15:00","updated_at":"2023-11-07 03:38:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://www.debian.org/security/2021/dsa-4967","name":"DSA-4967","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4967-1 squashfs-tools","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.debian.org/debian-lts-announce/2021/08/msg00030.html","name":"[debian-lts-announce] 20210831 [SECURITY] [DLA 2752-1] squashfs-tools security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2752-1] squashfs-tools security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSMRKVJMJFX3MB7D3PXJSYY3TLZROE5S/","name":"FEDORA-2021-9fb6da134f","refsource":"","tags":[],"title":"[SECURITY] Fedora 33 Update: squashfs-tools-4.5-3.20210913gite048580.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RAOZ4BKWAC4Y3U2K5MMW3S77HWWXHQDL/","name":"FEDORA-2021-cdbd827c1e","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: squashfs-tools-4.5-2.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646","name":"https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646","refsource":"MISC","tags":[],"title":"Unsquashfs: fix write outside destination directory exploit · plougher/squashfs-tools@79b5a55 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790","name":"https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790","refsource":"MISC","tags":[],"title":"Error: Page not found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://security.gentoo.org/glsa/202305-29","name":"GLSA-202305-29","refsource":"GENTOO","tags":[],"title":"squashfs-tools: Multiple Vulnerabilities (GLSA 202305-29) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RAOZ4BKWAC4Y3U2K5MMW3S77HWWXHQDL/","name":"FEDORA-2021-cdbd827c1e","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: squashfs-tools-4.5-2.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSMRKVJMJFX3MB7D3PXJSYY3TLZROE5S/","name":"FEDORA-2021-9fb6da134f","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 33 Update: squashfs-tools-4.5-3.20210913gite048580.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/plougher/squashfs-tools/issues/72","name":"https://github.com/plougher/squashfs-tools/issues/72","refsource":"MISC","tags":[],"title":"unsquashfs - unvalidated filepaths allow writing outside of destination · Issue #72 · plougher/squashfs-tools · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-40153","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-40153","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"40153","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"40153","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"40153","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"40153","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"40153","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"40153","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"40153","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"squashfs-tools_project","cpe5":"squashfs-tools","cpe6":"4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-40153","qid":"178783","title":"Debian Security Update for squashfs-tools (DSA 4967-1)"},{"cve":"CVE-2021-40153","qid":"178848","title":"Debian Security Update for squashfs-tools (DLA 2752-1)"},{"cve":"CVE-2021-40153","qid":"183809","title":"Debian Security Update for squashfs-tools (CVE-2021-40153)"},{"cve":"CVE-2021-40153","qid":"198475","title":"Ubuntu Security Notification for Squashfs-Tools Vulnerability (USN-5057-1)"},{"cve":"CVE-2021-40153","qid":"281858","title":"Fedora Security Update for squashfs (FEDORA-2021-cdbd827c1e)"},{"cve":"CVE-2021-40153","qid":"281940","title":"Fedora Security Update for squashfs (FEDORA-2021-9fb6da134f)"},{"cve":"CVE-2021-40153","qid":"355609","title":"Amazon Linux Security Advisory for squashfs-tools : ALAS2-2023-2152"},{"cve":"CVE-2021-40153","qid":"500656","title":"Alpine Linux Security Update for squashfs-tools"},{"cve":"CVE-2021-40153","qid":"504424","title":"Alpine Linux Security Update for squashfs-tools"},{"cve":"CVE-2021-40153","qid":"670832","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2021-2698)"},{"cve":"CVE-2021-40153","qid":"670833","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2021-2723)"},{"cve":"CVE-2021-40153","qid":"670954","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2021-2674)"},{"cve":"CVE-2021-40153","qid":"671028","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2021-2645)"},{"cve":"CVE-2021-40153","qid":"671232","title":"EulerOS Security Update for squashfs-tools (EulerOS-SA-2022-1189)"},{"cve":"CVE-2021-40153","qid":"710736","title":"Gentoo Linux squashfs-tools Multiple Vulnerabilities (GLSA 202305-29)"},{"cve":"CVE-2021-40153","qid":"755254","title":"SUSE Enterprise Linux Security Update for squashfs (SUSE-SU-2023:4424-1)"},{"cve":"CVE-2021-40153","qid":"901638","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for squashfs-tools (7463-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-40153","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646","refsource":"MISC","name":"https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646"},{"url":"https://github.com/plougher/squashfs-tools/issues/72","refsource":"MISC","name":"https://github.com/plougher/squashfs-tools/issues/72"},{"url":"https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790","refsource":"MISC","name":"https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790"},{"refsource":"FEDORA","name":"FEDORA-2021-cdbd827c1e","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RAOZ4BKWAC4Y3U2K5MMW3S77HWWXHQDL/"},{"refsource":"MLIST","name":"[debian-lts-announce] 20210831 [SECURITY] [DLA 2752-1] squashfs-tools security update","url":"https://lists.debian.org/debian-lts-announce/2021/08/msg00030.html"},{"refsource":"DEBIAN","name":"DSA-4967","url":"https://www.debian.org/security/2021/dsa-4967"},{"refsource":"FEDORA","name":"FEDORA-2021-9fb6da134f","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSMRKVJMJFX3MB7D3PXJSYY3TLZROE5S/"},{"refsource":"GENTOO","name":"GLSA-202305-29","url":"https://security.gentoo.org/glsa/202305-29"}]}},"nvd":{"publishedDate":"2021-08-27 15:15:00","lastModifiedDate":"2023-11-07 03:38:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:squashfs-tools_project:squashfs-tools:4.5:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"40153","Ordinal":"215870","Title":"CVE-2021-40153","CVE":"CVE-2021-40153","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"40153","Ordinal":"1","NoteData":"squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"40153","Ordinal":"2","NoteData":"2021-08-27","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"40153","Ordinal":"3","NoteData":"2021-09-28","Type":"Other","Title":"Modified"}]}}}