First published: Mon May 24 2021(Updated: )
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rpm Rpm | <4.18.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35937 is a race condition vulnerability found in rpm that allows a local unprivileged user to bypass checks and potentially gain root privileges.
CVE-2021-35937 poses a high threat to data confidentiality and integrity.
The affected software versions include rpm 4.18.0, Redhat Enterprise Linux 6.0, 7.0, 8.0, 9.0, and Fedoraproject Fedora 34.
The severity level of CVE-2021-35937 is medium with a CVSS score of 6.4.
To fix the CVE-2021-35937 vulnerability, it is recommended to update the affected software to a version that includes the fix or apply applicable patches.