CVE-2021-26910

Name
CVE-2021-26910
Description
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/netblue30/firejail/commit/97d8a03cad19501f017587cc4e47d8418273834b
Exploit https://unparalleled.eu/publications/2021/advisory-unpar-2021-0.txt
Release Notes https://github.com/netblue30/firejail/releases/tag/0.9.64.4
Exploit https://unparalleled.eu/blog/2021/20210208-rigged-race-against-firejail-for-local-root/
Exploit http://www.openwall.com/lists/oss-security/2021/02/09/1
Third Party Advisory https://www.debian.org/security/2021/dsa-4849
Third Party Advisory https://lists.debian.org/debian-lts-announce/2021/02/msg00015.html
GENTOO https://security.gentoo.org/glsa/202105-19

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:firejail_project:firejail:*:*:*:*:*:*:*:* firejail >= None < 0.9.64.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
firejail 3.13-community 0.9.64.4-r0 Stuart Cardall <developer@it-offshore.co.uk> fixed