Race condition in Zstandard - #VU50841
Published: February 22, 2021 / Updated: March 4, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition when creating files. The application creates a files with the default umask before chmod'ing to down to 0600. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
libzstd (Debian package)
Remediation
libzstd (Debian package) - update to 1.3.8+dfsg-3+deb10u2