CVE-2021-26910: Race Condition
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-26910?
CVE-2021-26910 is a vulnerability in Firejail before 0.9.64.4 that allows attackers to bypass intended access restrictions due to a race condition.
What is the severity of CVE-2021-26910?
CVE-2021-26910 has a severity value of 7, which is considered high.
How does CVE-2021-26910 affect Firejail?
CVE-2021-26910 affects Firejail versions before 0.9.64.4.
How can the CVE-2021-26910 vulnerability be fixed?
To fix the CVE-2021-26910 vulnerability, update Firejail to version 0.9.64.4 or later.
Are there any references for CVE-2021-26910?
Yes, you can find references for CVE-2021-26910 at the following links: [Reference 1](https://www.openwall.com/lists/oss-security/2021/02/08/5), [Reference 2](https://github.com/netblue30/firejail/commit/97d8a03cad19501f017587cc4e47d8418273834b), [Reference 3](https://unparalleled.eu/publications/2021/advisory-unpar-2021-0.txt).