CVE-2021-33632: TOCTOU Race Condition problem in iSulad
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad/main.C.
This issue affects iSulad: 2.0.18-13, from 2.1.4-1 through 2.1.4-2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33632?
CVE-2021-33632 has been assigned a severity level that indicates a moderate risk due to the potential for unauthorized access or control.
How do I fix CVE-2021-33632?
To mitigate CVE-2021-33632, update openEuler iSulad to version 2.1.4-2 or higher.
Which versions of openEuler iSulad are affected by CVE-2021-33632?
CVE-2021-33632 affects openEuler iSulad versions from 2.0.18-13 up to and including 2.1.4-1.
What are the consequences of exploiting CVE-2021-33632?
Exploitation of CVE-2021-33632 can lead to race condition vulnerabilities that may allow unauthorized access or execution of arbitrary code.
Is there a patch available for CVE-2021-33632?
Yes, a patch for CVE-2021-33632 is available in the latest release of openEuler iSulad.