« List of all CVEs

CVE-2021-3995

Published: 8/23/2022 Last updated: 8/3/2024 Reserved: 11/22/2021

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

vhdlib

Products affected (1)

Product Vendor Version
util-linux n/a Master Branch (ab0ee111)

References (18)