CVE-2021-3999: Buffer Overflow
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
Other sources
A flaw was found in glibc. The getcwd() function is affected by an off-by-one buffer overflow and underflow that may lead to memory corruption when the size of the buffer is exactly 1 byte.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-3999?
CVE-2021-3999 is a vulnerability in glibc that allows for an off-by-one buffer overflow and underflow in getcwd(), leading to potential memory corruption and arbitrary code execution.
What is the severity of CVE-2021-3999?
CVE-2021-3999 has a severity rating of 7.8 (High).
How does CVE-2021-3999 affect glibc?
CVE-2021-3999 affects glibc versions 2.28-10+deb10u2, 2.31-13+deb11u6, 2.31-13+deb11u7, 2.36-9+deb12u2, 2.36-9+deb12u3, and 2.37-12.
What is the remedy for CVE-2021-3999 on Debian Debian Linux 10.0?
CVE-2021-3999 can be fixed on Debian Debian Linux 10.0 by updating glibc to version 2.31 or higher.
Are Netapp E-series Performance Analyzer and Netapp Nfs Plug-in affected by CVE-2021-3999?
Yes, Netapp E-series Performance Analyzer and Netapp Nfs Plug-in are affected by CVE-2021-3999.