Medium severity5.5NVD Advisory· Published Aug 23, 2022· Updated Jun 17, 2026
CVE-2021-3995
CVE-2021-3995
Description
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
25- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- util-linux/libmountdescription
- Range: <2.37.3
- osv-coords20 versionspkg:rpm/opensuse/libeconf&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python3-libmount&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/shadow&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/util-linux&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/util-linux&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/util-linux-systemd&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/libeconf&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/libeconf&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/libeconf&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/libeconf&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Transactional%20Server%2015%20SP3pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/util-linux&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/util-linux&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/util-linux&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/util-linux-systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/util-linux-systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/util-linux-systemd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/util-linux-systemd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3
< 0.4.4+git20220104.962774f-150300.3.6.2+ 19 more
- (no CPE)range: < 0.4.4+git20220104.962774f-150300.3.6.2
- (no CPE)range: < 2.36.2-150300.4.14.2
- (no CPE)range: < 4.8.1-150300.4.3.8
- (no CPE)range: < 2.36.2-150300.4.14.3
- (no CPE)range: < 2.37.3-1.1
- (no CPE)range: < 2.36.2-150300.4.14.2
- (no CPE)range: < 0.4.4+git20220104.962774f-150300.3.6.2
- (no CPE)range: < 0.4.4+git20220104.962774f-150300.3.6.2
- (no CPE)range: < 0.4.4+git20220104.962774f-150300.3.6.2
- (no CPE)range: < 0.4.4+git20220104.962774f-150300.3.6.2
- (no CPE)range: < 4.8.1-150300.4.3.8
- (no CPE)range: < 4.8.1-150300.4.3.8
- (no CPE)range: < 4.8.1-150300.4.3.8
- (no CPE)range: < 2.36.2-150300.4.14.3
- (no CPE)range: < 2.36.2-150300.4.14.3
- (no CPE)range: < 2.36.2-150300.4.14.3
- (no CPE)range: < 2.36.2-150300.4.14.2
- (no CPE)range: < 2.36.2-150300.4.14.2
- (no CPE)range: < 2.36.2-150300.4.14.2
- (no CPE)range: < 2.36.2-150300.4.14.2
Patches
Vulnerability mechanics
References
9- github.com/util-linux/util-linux/commit/57202f5713afa2af20ffbb6ab5331481d0396f8dnvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2022/01/24/2nvdExploitMailing ListPatchThird Party Advisory
- packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2022/Dec/4nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2022/11/30/2nvdMailing ListThird Party Advisory
- mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.37/v2.37.3-ReleaseNotesnvdRelease NotesVendor Advisory
- security.netapp.com/advisory/ntap-20221209-0002/nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdBroken LinkIssue Tracking
- security.gentoo.org/glsa/202401-08nvd
News mentions
0No linked articles in our index yet.