CVE-2021-3995 Details
Description
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kernel util-linux | >= 2.34, < 2.37.3 |
CPE
Remediation
| |
| fedoraproject fedora | 35 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 7, 2024 | CVE Modified | [email protected] |
| Feb 3, 2023 | Modified Analysis | [email protected] |
| Dec 9, 2022 | CVE Modified | [email protected] |
| Dec 9, 2022 | CVE Modified | [email protected] |
| Dec 9, 2022 | CVE Modified | [email protected] |
| Dec 7, 2022 | Modified Analysis | [email protected] |
| Dec 1, 2022 | CVE Modified | [email protected] |
| Oct 24, 2022 | Reanalysis | [email protected] |
| Aug 29, 2022 | Initial Analysis | [email protected] |