Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-36086

16
FAUCET Score

CVE-2021-36086 describes a use-after-free vulnerability within the CIL compiler of SELinux 3.2, specifically affecting Fedora and SELinux Project distributions. This flaw, rated with a low CVSS score of 3.3, could lead to a denial of service (availability impact) if a local, low-privileged attacker successfully exploits it without user interaction. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.59%
Probability of exploitation in next 30 days
EPSS Percentile
44.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0059 is in the 96th percentile among its peer group of 1,509 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libsepol-0:2.9-3.el8
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libsepol

Vendor Advisories (1)

redhatCVE-2021-36086Moderate

libsepol: use-after-free in cil_reset_classpermission()

Apr 19, 2021

References

lists.debian.org / debian-lts-announce/2024/10/msg00021.html
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20250207-0004
Third Party Advisory
bugs.chromium.org / p/oss-fuzz/issues/detail
ExploitIssue TrackingPatchThird Party Advisory
github.com / google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-536.yaml
Third Party Advisory
github.com / SELinuxProject/selinux/commit/c49a8ea09501ad66e799ea41b8154b6770fec2c8
PatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR
Broken Link