CVE-2021-3998: High severity gnu c library (glibc) vulnerability
A flaw was found in glibc. The realpath function may sometimes return a unexpected value, potentially leading to disclosure of sensitive data.
Other sources
A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3998?
CVE-2021-3998 is a vulnerability in glibc that allows the realpath() function to return unexpected values, potentially leading to information leakage and disclosure of sensitive data.
How severe is CVE-2021-3998?
CVE-2021-3998 has a severity rating of 7.5 out of 10, indicating a high severity.
Which software is affected by CVE-2021-3998?
CVE-2021-3998 affects GNU glibc, NetApp ONTAP Select Deploy administration utility, Apple macOS Ventura, Apple macOS Big Sur, Apple macOS Monterey, and Netapp H410c Firmware.
How can I fix CVE-2021-3998?
To fix CVE-2021-3998, update the affected software to the latest version provided by the respective vendors.
Where can I find more information about CVE-2021-3998?
You can find more information about CVE-2021-3998 in the references provided: [Reference 1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2039674), [Reference 2](https://sourceware.org/bugzilla/show_bug.cgi?id=28770), [Reference 3](https://patchwork.sourceware.org/project/glibc/patch/20220113055920.3155918-1-siddhesh@sourceware.org/).