Wind River Support Network

HomeDefectsLIN10-9029
Fixed

LIN10-9029 : Security Advisory - squashfs-tools - CVE-2021-40153

Created: Aug 28, 2021    Updated: May 13, 2022
Resolved Date: Sep 10, 2021
Found In Version: 10.17.41.1
Fix Version: 10.17.41.25
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CREATE(Triage):(User=admin) CVE-2021-40153 (https://nvd.nist.gov/vuln/detail/CVE-2021-40153)

CVEs


Live chat
Online