CVE-2021-43395
MEDIUM
5,5
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0006
Percentile
0,2th
Updated
EPSS Score Trend (Last 90 Days)
667
Improper Locking
DraftCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Applicable Platforms
All platforms may be affected
Operating System
Illumos by Illumos
Version Range Affected
To
2022-01-18
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:illumos:illumos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Openindiana by Openindiana
CPE Identifier
View Detailed Analysis
cpe:2.3:o:openindiana:openindiana:hipster_2021.04:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Smartos by Joyent
CPE Identifier
View Detailed Analysis
cpe:2.3:o:joyent:smartos:20210923:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Solaris by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Solaris by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Omnios by Omniosce
CPE Identifier
View Detailed Analysis
cpe:2.3:o:omniosce:omnios:r151038:*:*:*:community:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/illumos/illumos-gate/blob/069654420de4aade43c63c43cd2896e669…
https://github.com/illumos/illumos-gate/blob/b3403853e80914bd0aade9b5b605da4878…
https://github.com/illumos/illumos-gate/commit/f859e7171bb5db34321e45585839c6c3…
https://illumos.topicbox.com/groups/developer/T1c9e4f27f8c2f959/security-heads-…
https://jgardner100.wordpress.com/2022/01/20/security-heads-up/
https://kebe.com/blog/?p=505
https://www.illumos.org/issues/14424
https://www.oracle.com/security-alerts/cpujan2022.html
http://www.tribblix.org/relnotes.html
https://github.com/illumos/illumos-gate/blob/069654420de4aade43c63c43cd2896e669…
https://github.com/illumos/illumos-gate/blob/b3403853e80914bd0aade9b5b605da4878…
https://github.com/illumos/illumos-gate/commit/f859e7171bb5db34321e45585839c6c3…
https://illumos.topicbox.com/groups/developer/T1c9e4f27f8c2f959/security-heads-…
https://jgardner100.wordpress.com/2022/01/20/security-heads-up/
https://kebe.com/blog/?p=505
https://www.illumos.org/issues/14424
https://www.oracle.com/security-alerts/cpujan2022.html
http://www.tribblix.org/relnotes.html