CVE-2021-43412: Use After Free
Published Nov 7, 2021
·Updated
An issue was discovered in GNU Hurd before 0.9 20210404-9. libports accepts fake notification messages from any client on any port, which can lead to port use-after-free. This can be exploited for local privilege escalation to get full root access.
Affected Software
1 affected component
GNU Hurd<0.9.20210404-9
Event History
Nov 7, 2021
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43412?
CVE-2021-43412 has a high severity rating due to its potential for local privilege escalation leading to full root access.
2
How do I fix CVE-2021-43412?
To fix CVE-2021-43412, update to GNU Hurd version 0.9 20210404-9 or later.
3
What type of attack does CVE-2021-43412 enable?
CVE-2021-43412 enables local privilege escalation attacks through the exploitation of port use-after-free vulnerabilities.
4
Which versions of GNU Hurd are affected by CVE-2021-43412?
CVE-2021-43412 affects all versions of GNU Hurd before 0.9 20210404-9.
5
Is CVE-2021-43412 remote or local in nature?
CVE-2021-43412 is a local vulnerability, requiring access to the system to exploit.