vulnerability

SUSE: CVE-2021-3995: SUSE Linux Security Advisory

Severity
5
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:C)
Published
Feb 9, 2022
Added
Mar 5, 2022
Modified
Jan 28, 2025

Description

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

Solution(s)

suse-upgrade-libblkid-develsuse-upgrade-libblkid-devel-32bitsuse-upgrade-libblkid-devel-staticsuse-upgrade-libblkid1suse-upgrade-libblkid1-32bitsuse-upgrade-libeconf-develsuse-upgrade-libeconf0suse-upgrade-libeconf0-32bitsuse-upgrade-libfdisk-develsuse-upgrade-libfdisk-devel-32bitsuse-upgrade-libfdisk-devel-staticsuse-upgrade-libfdisk1suse-upgrade-libfdisk1-32bitsuse-upgrade-libmount-develsuse-upgrade-libmount-devel-32bitsuse-upgrade-libmount-devel-staticsuse-upgrade-libmount1suse-upgrade-libmount1-32bitsuse-upgrade-libsmartcols-develsuse-upgrade-libsmartcols-devel-32bitsuse-upgrade-libsmartcols-devel-staticsuse-upgrade-libsmartcols1suse-upgrade-libsmartcols1-32bitsuse-upgrade-libuuid-develsuse-upgrade-libuuid-devel-32bitsuse-upgrade-libuuid-devel-staticsuse-upgrade-libuuid1suse-upgrade-libuuid1-32bitsuse-upgrade-login_defssuse-upgrade-python3-libmountsuse-upgrade-shadowsuse-upgrade-util-linuxsuse-upgrade-util-linux-langsuse-upgrade-util-linux-systemdsuse-upgrade-uuidd
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.