Wind River Support Network

HomeDefectsLIN1021-1334
Fixed

LIN1021-1334 : Security Advisory - squashfs-tools - CVE-2021-40153

Created: Aug 28, 2021    Updated: May 13, 2022
Resolved Date: Sep 17, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.5
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CREATE(Triage):(User=admin) CVE-2021-40153 (https://nvd.nist.gov/vuln/detail/CVE-2021-40153)

CVEs


Live chat
Online