CVE-2021-3732: Infoleak
A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.
Other sources
A flaw was found in the Linux kernel’s OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.
A flaw was found in the Linux kernels implementation of overlayfs where a local attacker with an unpriviledged account who has the ability to mount a filesystem can abuse a logic bug in the overlayfs code which can inadvertantly reveal files hidden in the orignal mount.
References:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=427215d85e8d https://bugzilla.redhat.com/showbug.cgi?id=1993131
— Red Hat
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-3732?
CVE-2021-3732 is classified as a medium severity vulnerability.
How do I fix CVE-2021-3732?
To fix CVE-2021-3732, update the kernel package to the recommended versions provided by your Linux distribution.
Who is affected by CVE-2021-3732?
CVE-2021-3732 affects users of certain versions of the Linux kernel, specifically those utilizing OverlayFS functionality.
What is the impact of CVE-2021-3732?
The impact of CVE-2021-3732 is that a local user may gain unauthorized access to hidden files.
Is CVE-2021-3732 being actively exploited?
As of now, there is no public information indicating that CVE-2021-3732 is actively being exploited in the wild.