vulnerability
SUSE: CVE-2021-3995: SUSE Linux Security Advisory
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | Feb 9, 2022 | Mar 5, 2022 | Jan 28, 2025 |
Severity
5
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:C)
Published
Feb 9, 2022
Added
Mar 5, 2022
Modified
Jan 28, 2025
Description
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
Solution(s)
suse-upgrade-libblkid-develsuse-upgrade-libblkid-devel-32bitsuse-upgrade-libblkid-devel-staticsuse-upgrade-libblkid1suse-upgrade-libblkid1-32bitsuse-upgrade-libeconf-develsuse-upgrade-libeconf0suse-upgrade-libeconf0-32bitsuse-upgrade-libfdisk-develsuse-upgrade-libfdisk-devel-32bitsuse-upgrade-libfdisk-devel-staticsuse-upgrade-libfdisk1suse-upgrade-libfdisk1-32bitsuse-upgrade-libmount-develsuse-upgrade-libmount-devel-32bitsuse-upgrade-libmount-devel-staticsuse-upgrade-libmount1suse-upgrade-libmount1-32bitsuse-upgrade-libsmartcols-develsuse-upgrade-libsmartcols-devel-32bitsuse-upgrade-libsmartcols-devel-staticsuse-upgrade-libsmartcols1suse-upgrade-libsmartcols1-32bitsuse-upgrade-libuuid-develsuse-upgrade-libuuid-devel-32bitsuse-upgrade-libuuid-devel-staticsuse-upgrade-libuuid1suse-upgrade-libuuid1-32bitsuse-upgrade-login_defssuse-upgrade-python3-libmountsuse-upgrade-shadowsuse-upgrade-util-linuxsuse-upgrade-util-linux-langsuse-upgrade-util-linux-systemdsuse-upgrade-uuidd

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.