CVE-2021-43411 Information
Jun 07, 2022
cve
Description
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable there’s a window of time when the process already has the new privileges but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://salsa.debian.org/hurd-team/hurd/-/blob/4d1b079411e2f40576e7b58f9b5b78f733a2beda/debian/patches/0034-proc-Use-UIDs-for-evaluating-permissions.patch https://lists.gnu.org/archive/html/bug-hurd/2021-05/msg00079.html https://www.mail-archive.com/bug-hurd@gnu.org/msg32112.html
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.5
Share on: