Medium severity6.7NVD Advisory· Published Aug 26, 2022· Updated Jun 17, 2026
CVE-2021-35939
CVE-2021-35939
Description
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- CVE-2017-7500 and CVE-2017-7501/CVE-2017-7500 and CVE-2017-7501description
- osv-coords18 versionspkg:rpm/almalinux/python3-rpmpkg:rpm/almalinux/rpmpkg:rpm/almalinux/rpm-apidocspkg:rpm/almalinux/rpm-buildpkg:rpm/almalinux/rpm-build-libspkg:rpm/almalinux/rpm-cronpkg:rpm/almalinux/rpm-develpkg:rpm/almalinux/rpm-libspkg:rpm/almalinux/rpm-plugin-auditpkg:rpm/almalinux/rpm-plugin-fapolicydpkg:rpm/almalinux/rpm-plugin-imapkg:rpm/almalinux/rpm-plugin-prioresetpkg:rpm/almalinux/rpm-plugin-selinuxpkg:rpm/almalinux/rpm-plugin-syslogpkg:rpm/almalinux/rpm-plugin-systemd-inhibitpkg:rpm/almalinux/rpm-signpkg:rpm/almalinux/rpm-sign-libspkg:rpm/opensuse/rpm&distro=openSUSE%20Tumbleweed
< 4.16.1.3-27.el9_3+ 17 more
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.14.3-28.el8_9
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.16.1.3-27.el9_3
- (no CPE)range: < 4.18.0-1.1
Patches
Vulnerability mechanics
References
6- github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5eb23b83a6377d556nvdPatchThird Party Advisory
- github.com/rpm-software-management/rpm/pull/1919nvdPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- access.redhat.com/security/cve/CVE-2021-35939nvdThird Party Advisory
- rpm.org/wiki/Releases/4.18.0nvdRelease NotesVendor Advisory
- security.gentoo.org/glsa/202210-22nvdThird Party Advisory
News mentions
0No linked articles in our index yet.