CVE-2021-24032: Medium severity Facebook Zstandard vulnerability

Published Feb 12, 2021
·
Updated

Beginning in v1.4.1 and prior to v1.4.9 due to an incomplete fix for CVE-2021-24031 the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

Other sources

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

While the final file mode is reflective of the input file, when compressing or uncompressing, the file can temporarily gain greater permissions than the input and potentially leading to security issues (especially if large files are being handled).

References:

https://github.com/facebook/zstd/issues/2491 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=982519

Red Hat

Affected Software

88 affected componentsFixes available
Facebook Zstandard>=1.4.1<1.4.9
redhat/zstd<1.4.9
1.4.9
Microsoft azl3 ceph 18.2.2-8<18.2.2-5
18.2.2-5
Microsoft cbl2 ceph 16.2.10-7<16.2.10-3
16.2.10-3
Microsoft cm1 zstd 1.4.9-1<1.4.9-1
1.4.9-1
Microsoft cbl2 ceph 16.2.10-3<16.2.10-3
16.2.10-3
Microsoft azl3 ceph 18.2.2-5<18.2.2-5
18.2.2-5
Microsoft python3-ceph-argparse-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft libcephfs-devel-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-grafana-dashboards-16.2.10-3.cm2.noarch.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-prometheus-alerts-16.2.10-3.cm2.noarch.rpm<16.2.10-3
16.2.10-3
Microsoft python3-cephfs-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft libcephfs2-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft librbd1-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-rbd-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft libradosstriper-devel-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft rados-objclass-devel-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft libradosstriper1-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-ceph-common-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft librbd-devel-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-rados-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft librados-devel-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-rgw-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft libradospp-devel-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft librados2-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-osd-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft rbd-nbd-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-immutable-object-cache-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft rbd-fuse-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-radosgw-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft rbd-mirror-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft librgw2-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mgr-rook-16.2.10-3.cm2.noarch.rpm<16.2.10-3
16.2.10-3
Microsoft librgw-devel-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-fuse-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mgr-k8sevents-16.2.10-3.cm2.noarch.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mgr-dashboard-16.2.10-3.cm2.noarch.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mgr-cephadm-16.2.10-3.cm2.noarch.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mon-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mgr-modules-core-16.2.10-3.cm2.noarch.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mds-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mgr-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft rados-objclass-devel-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-ceph-common-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-common-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-ceph-argparse-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-cephfs-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft libcephfs2-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft libcephfs-devel-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft librbd-devel-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-rbd-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft cephadm-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft libradosstriper-devel-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-rados-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft librbd1-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft libradosstriper1-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft librgw2-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-base-16.2.10-3.cm2.aarch64.rpm<16.2.10-3
16.2.10-3
Microsoft librgw-devel-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft librados2-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft librados-devel-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-radosgw-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft rbd-mirror-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft python3-rgw-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft libradospp-devel-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-osd-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft rbd-nbd-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-immutable-object-cache-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft rbd-fuse-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-fuse-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mon-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft cephadm-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mgr-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-common-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-mds-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-base-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft ceph-16.2.10-3.cm2.x86_64.rpm<16.2.10-3
16.2.10-3
Microsoft zstd-devel-1.4.9-1.cm1.aarch64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-libs-1.4.9-1.cm1.aarch64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-debuginfo-1.4.9-1.cm1.x86_64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-doc-1.4.9-1.cm1.aarch64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-1.4.9-1.cm1.aarch64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-debuginfo-1.4.9-1.cm1.aarch64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-doc-1.4.9-1.cm1.x86_64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-libs-1.4.9-1.cm1.x86_64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-devel-1.4.9-1.cm1.x86_64.rpm<1.4.9-1
1.4.9-1
Microsoft zstd-1.4.9-1.cm1.x86_64.rpm<1.4.9-1
1.4.9-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/zstd to a version that resolves this vulnerability.

    Fixed in 1.4.9
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.2.2-5
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 16.2.10-3
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.4.9-1
  5. Upgrade

    Upgrade zstd (Zstandard command-line utility) to a version that resolves this vulnerability.

    Fixed in 1.4.9
  6. Compensating control

    Use a filesystem permission/containment control for zstd output during compress/uncompress (since output files can temporarily gain greater permissions) to prevent unintended parties from momentarily reading/writing the created output files.

Event History

Feb 12, 2021
Data Sourced
via Red Hat·11:42 AM
DescriptionSeverityAffected Software
Mar 4, 2021
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionWeakness
Jul 30, 2021
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·12:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-24032?

CVE-2021-24032 is a vulnerability in the Zstandard command-line utility that creates output files with default permissions, which could momentarily make them readable or writable to unintended users.

2

What is the severity of CVE-2021-24032?

CVE-2021-24032 has a severity score of 4.7, which is classified as medium.

3

How does CVE-2021-24032 affect Facebook Zstandard?

CVE-2021-24032 affects Facebook Zstandard versions between 1.4.1 and 1.4.9.

4

Are there any known fixes for CVE-2021-24032?

Yes, updating to Facebook Zstandard version 1.4.9 or later fixes the vulnerability.

5

Where can I find more information about CVE-2021-24032?

You can find more information about CVE-2021-24032 on the Debian bug report, GitHub issue, and Facebook security advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203