CVE-2021-43395: Medium severity illumos vulnerability
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-43395.
What is the severity level of CVE-2021-43395?
The severity level of CVE-2021-43395 is medium with a score of 5.5.
Which software versions are affected by CVE-2021-43395?
CVE-2021-43395 affects illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923.
How can a local unprivileged user exploit CVE-2021-43395?
A local unprivileged user can cause a deadlock and kernel panic by crafting rename and rmdir calls on tmpfs filesystems.
Are there any references or resources available for CVE-2021-43395?
Yes, you can find more information about CVE-2021-43395 at the following links: [http://www.tribblix.org/relnotes.html](http://www.tribblix.org/relnotes.html), [https://github.com/illumos/illumos-gate/blob/069654420de4aade43c63c43cd2896e66945fc8a/usr/src/uts/common/fs/tmpfs/tmp_vnops.c](https://github.com/illumos/illumos-gate/blob/069654420de4aade43c63c43cd2896e66945fc8a/usr/src/uts/common/fs/tmpfs/tmp_vnops.c), [https://github.com/illumos/illumos-gate/blob/b3403853e80914bd0aade9b5b605da4878078173/usr/src/uts/common/fs/tmpfs/tmp_dir.c](https://github.com/illumos/illumos-gate/blob/b3403853e80914bd0aade9b5b605da4878078173/usr/src/uts/common/fs/tmpfs/tmp_dir.c)