Lucene search

K
cveMitreCVE-2021-43395
HistoryDec 26, 2022 - 6:15 a.m.

CVE-2021-43395

2022-12-2606:15:10
CWE-667
mitre
web.nvd.nist.gov
46
illumos
omnios
openindiana
smartos
solaris
local user
privilege escalation
filesystem manipulation
cve-2021-43395
nvd

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

29.7%

An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.

Affected configurations

Nvd
Node
illumosillumosRange<2022-01-18
Node
omniosceomniosMatchr151038community
Node
openindianaopenindianaMatchhipster_2021.04
Node
joyentsmartosMatch20210923
Node
oraclesolarisMatch10
OR
oraclesolarisMatch11
VendorProductVersionCPE
illumosillumos*cpe:2.3:o:illumos:illumos:*:*:*:*:*:*:*:*
omniosceomniosr151038cpe:2.3:o:omniosce:omnios:r151038:*:*:*:community:*:*:*
openindianaopenindianahipster_2021.04cpe:2.3:o:openindiana:openindiana:hipster_2021.04:*:*:*:*:*:*:*
joyentsmartos20210923cpe:2.3:o:joyent:smartos:20210923:*:*:*:*:*:*:*
oraclesolaris10cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
oraclesolaris11cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

29.7%

Related for CVE-2021-43395