First published: Fri Apr 29 2022(Updated: )
Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other services running in the same machine.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME gnome-shell |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3982 is a vulnerability in Linux distributions using CAP_SYS_NICE for gnome-shell that may allow for privilege escalation.
Linux distributions using CAP_SYS_NICE for gnome-shell are affected by CVE-2021-3982, which may result in a privilege escalation issue.
The severity of CVE-2021-3982 is medium, with a severity value of 5.5.
An attacker with low privilege permissions can exploit CVE-2021-3982 by taking advantage of the way CAP_SYS_NICE is implemented and loading code to increase its process scheduler priority.
Yes, you can find references for CVE-2021-3982 at the following links: [link1](https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/2284), [link2](https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/2060).