Medium severity5.5NVD Advisory· Published Aug 23, 2022· Updated Jun 17, 2026
CVE-2021-3800
CVE-2021-3800
Description
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*range: <2.62.5
- (no CPE)range: <2.63.6
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- glib/glibdescription
- osv-coords6 versionspkg:rpm/almalinux/glib2-docpkg:rpm/almalinux/glib2-staticpkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5
< 2.56.4-156.el8+ 5 more
- (no CPE)range: < 2.56.4-156.el8
- (no CPE)range: < 2.56.4-156.el8
- (no CPE)range: < 2.48.2-12.25.1
- (no CPE)range: < 2.48.2-12.25.1
- (no CPE)range: < 2.48.2-12.25.1
- (no CPE)range: < 2.48.2-12.25.1
Patches
Vulnerability mechanics
References
6- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- gitlab.gnome.org/GNOME/glib/-/commit/3529bb4450a51995nvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2017/06/23/8nvdExploitMailing ListPatchThird Party Advisory
- access.redhat.com/security/cve/CVE-2021-3800nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/09/msg00020.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20221028-0004/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.