CVE-2021-3996 is a logic error in the libmount library of util-linux, affecting Fedora and its util-linux packages. This flaw allows an unprivileged local user to unmount other users' world-writable FUSE filesystems or those mounted in world-writable directories. Rated Medium severity (CVSS 5.5), it can lead to a denial of service for applications relying on these filesystems. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.34, < 2.37.3CPE matchmatch criteria | cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
Aug 9, 2022util-linux: Unauthorized unmount of filesystems in libmount
Jan 24, 2022