VYPR
High severity7.5NVD Advisory· Published Nov 7, 2021· Updated Jun 17, 2026

CVE-2021-43411

CVE-2021-43411

Description

An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • GNU/Hurd2 versions
    cpe:2.3:a:gnu:hurd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gnu:hurd:*:*:*:*:*:*:*:*range: <0.9.20210404-9
    • (no CPE)range: < 0.9 20210404-9
  • GNU/GNU Hurddescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.