vulnerability

Amazon Linux 2023: CVE-2021-35937: Medium priority package update for rpm

Severity
6
CVSS
(AV:L/AC:H/Au:M/C:C/I:C/A:C)
Published
Jun 30, 2021
Added
Feb 17, 2025
Modified
Jul 4, 2025

Description

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Solutions

amazon-linux-2023-upgrade-python3-rpmamazon-linux-2023-upgrade-python3-rpm-debuginfoamazon-linux-2023-upgrade-rpmamazon-linux-2023-upgrade-rpm-apidocsamazon-linux-2023-upgrade-rpm-buildamazon-linux-2023-upgrade-rpm-build-debuginfoamazon-linux-2023-upgrade-rpm-build-libsamazon-linux-2023-upgrade-rpm-build-libs-debuginfoamazon-linux-2023-upgrade-rpm-cronamazon-linux-2023-upgrade-rpm-debuginfoamazon-linux-2023-upgrade-rpm-debugsourceamazon-linux-2023-upgrade-rpm-develamazon-linux-2023-upgrade-rpm-devel-debuginfoamazon-linux-2023-upgrade-rpm-libsamazon-linux-2023-upgrade-rpm-libs-debuginfoamazon-linux-2023-upgrade-rpm-plugin-auditamazon-linux-2023-upgrade-rpm-plugin-audit-debuginfoamazon-linux-2023-upgrade-rpm-plugin-fapolicydamazon-linux-2023-upgrade-rpm-plugin-fapolicyd-debuginfoamazon-linux-2023-upgrade-rpm-plugin-imaamazon-linux-2023-upgrade-rpm-plugin-ima-debuginfoamazon-linux-2023-upgrade-rpm-plugin-prioresetamazon-linux-2023-upgrade-rpm-plugin-prioreset-debuginfoamazon-linux-2023-upgrade-rpm-plugin-selinuxamazon-linux-2023-upgrade-rpm-plugin-selinux-debuginfoamazon-linux-2023-upgrade-rpm-plugin-syslogamazon-linux-2023-upgrade-rpm-plugin-syslog-debuginfoamazon-linux-2023-upgrade-rpm-plugin-systemd-inhibitamazon-linux-2023-upgrade-rpm-plugin-systemd-inhibit-debuginfoamazon-linux-2023-upgrade-rpm-signamazon-linux-2023-upgrade-rpm-sign-debuginfoamazon-linux-2023-upgrade-rpm-sign-libsamazon-linux-2023-upgrade-rpm-sign-libs-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.