CVE-2022-21658 is a race condition vulnerability in the std::fs::remove_dir_all function of the Rust standard library, affecting Rust versions 1.0.0 through 1.58.0. This flaw allows an attacker to trick privileged programs into deleting files or directories they shouldn't have access to, impacting products like Rust-lang, Apple, and Fedora Project. Rated Medium severity (CVSS 6.3), it requires local access and high attack complexity, with successful exploitation leading to high integrity and availability impacts. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, <= 1.58.0CPE matchmatch criteria | cpe:2.3:a:rust-lang:rust:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
< 15.4CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.