CVE-2021-43411: Race Condition
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43411?
CVE-2021-43411 is considered to have a critical severity due to its potential for gaining full root access.
How do I fix CVE-2021-43411?
To fix CVE-2021-43411, update your GNU Hurd installation to version 0.9 20210404-9 or later.
What types of systems are affected by CVE-2021-43411?
CVE-2021-43411 affects all versions of GNU Hurd prior to 0.9 20210404-9.
What is the impact of CVE-2021-43411?
The impact of CVE-2021-43411 allows an attacker to exploit a vulnerability in setuid executables to gain elevated privileges.
Is there any workaround for CVE-2021-43411?
There are no known workarounds for CVE-2021-43411; updating to the patched version is necessary.