First published: Mon Feb 08 2021(Updated: )
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firejail | 0.9.58.2-2+deb10u3 0.9.64.4-2+deb11u1 0.9.72-2 | |
Firejail Project Firejail | <0.9.64.4 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26910 is a vulnerability in Firejail before 0.9.64.4 that allows attackers to bypass intended access restrictions due to a race condition.
CVE-2021-26910 has a severity value of 7, which is considered high.
CVE-2021-26910 affects Firejail versions before 0.9.64.4.
To fix the CVE-2021-26910 vulnerability, update Firejail to version 0.9.64.4 or later.
Yes, you can find references for CVE-2021-26910 at the following links: [Reference 1](https://www.openwall.com/lists/oss-security/2021/02/08/5), [Reference 2](https://github.com/netblue30/firejail/commit/97d8a03cad19501f017587cc4e47d8418273834b), [Reference 3](https://unparalleled.eu/publications/2021/advisory-unpar-2021-0.txt).