Wind River Support Network

HomeDefectsLIN1021-2429
Fixed

LIN1021-2429 : Security Advisory - glibc - CVE-2021-3999

Created: Jan 12, 2022    Updated: Aug 25, 2022
Resolved Date: Mar 22, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.11
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Toolchain

Description

A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.

https://nvd.nist.gov/vuln/detail/CVE-2021-3999

CVEs


Live chat
Online