First published: Thu Nov 18 2021(Updated: )
A flaw was found in glibc. The realpath function may sometimes return a unexpected value, potentially leading to disclosure of sensitive data.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library (glibc) | >=2.33<2.35 | |
NetApp ONTAP Select Deploy | ||
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
All of | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
debian/glibc | 2.31-13+deb11u11 2.31-13+deb11u10 2.36-9+deb12u10 2.36-9+deb12u7 2.41-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3998 is a vulnerability in glibc that allows the realpath() function to return unexpected values, potentially leading to information leakage and disclosure of sensitive data.
CVE-2021-3998 has a severity rating of 7.5 out of 10, indicating a high severity.
CVE-2021-3998 affects GNU glibc, NetApp ONTAP Select Deploy administration utility, Apple macOS Ventura, Apple macOS Big Sur, Apple macOS Monterey, and Netapp H410c Firmware.
To fix CVE-2021-3998, update the affected software to the latest version provided by the respective vendors.
You can find more information about CVE-2021-3998 in the references provided: [Reference 1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2039674), [Reference 2](https://sourceware.org/bugzilla/show_bug.cgi?id=28770), [Reference 3](https://patchwork.sourceware.org/project/glibc/patch/20220113055920.3155918-1-siddhesh@sourceware.org/).