Race condition in Rust Programming Language - CVE-2022-21658

 

Race condition in Rust Programming Language - CVE-2022-21658

Published: January 21, 2022 / Updated: January 23, 2022


Vulnerability identifier: #VU59898
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21658
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to a race condition in std::fs::remove_dir_all. A remote attacker can exploit the race, escalate privileges and delete arbitrary files on the system.


Affected software

Rust Programming Language
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Fedora
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
macOS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
watchOS
iPadOS
Apple iOS
tvOS
rust-below
rust-askalono-cli
rust-cargo-c
rust-skim
zola
rust-lsd
rust-python-launcher
rust-thread_local
rust-cargo-insta
rls-debuginfo
rust-analysis
rust-src
rust-debuginfo
cargo
rust
rls
cargo-debuginfo
cargo1.55
cargo1.55-debuginfo
rust1.55
rust1.55-debuginfo
rust1.56-debuginfo
rust1.56
cargo1.56-debuginfo
cargo1.56
rust1.57
cargo1.57
rust1.57-debuginfo
cargo1.57-debuginfo
rust1.58-debuginfo
rust1.58
cargo1.58-debuginfo
cargo1.58
rust-toolset
rust-std-static-wasm32-wasi
rust-std-static-wasm32-unknown-unknown
clippy
rust-doc
rust-std-static
rustfmt
rust-lldb
rust-gdb
cargo-doc
rust-debugger-common
rust1.59-debuginfo
rust1.59
cargo1.59-debuginfo
cargo1.59
rust-oxipng
rust-afterburn
rust-fd-find
rust-tokei
rust-ripgrep
llvm13

How to mitigate CVE-2022-21658

Install updates from vendor's website.

Rust Programming Language - update to 1.58.1
macOS - update to 12.3 21E230
rust-below - addressed in versions 0.4.1-3.fc34, 0.4.1-3.fc35, 0.4.1-3.fc36
rust-askalono-cli - addressed in versions 0.4.4-3.fc34, 0.4.4-3.fc35, 0.4.4-3.fc36
rust-cargo-c - addressed in versions 0.9.2-6.fc34, 0.9.2-6.fc35, 0.9.2-6.fc36
rust-skim - addressed in versions 0.9.4-8.fc34, 0.9.4-8.fc35, 0.9.4-8.fc36
zola - addressed in versions 0.12.2-10.fc34, 0.12.2-10.fc35, 0.12.2-10.fc36
rust-lsd - addressed in versions 0.20.1-8.fc34, 0.20.1-8.fc35, 0.20.1-8.fc36
rust-python-launcher - addressed in versions 1.0.0-4.fc34, 1.0.0-4.fc35, 1.0.0-4.fc36
rust-thread_local - addressed in versions 1.1.4-1.fc34, 1.1.4-1.fc35, 1.1.4-1.fc36
rust-cargo-insta - addressed in versions 1.8.0-3.fc34, 1.8.0-3.fc35, 1.8.0-3.fc36
rls-debuginfo - update to 1.53.0-22.1
rust-analysis - update to 1.53.0-22.1
rust-src - update to 1.53.0-22.1
rust-debuginfo - update to 1.53.0-22.1
cargo - addressed in versions 1.53.0-22.1, 1.59.0-150300.21.20.1
rust - addressed in versions 1.53.0-22.1, 1.59.0-150300.21.20.1
rls - update to 1.53.0-22.1
cargo-debuginfo - update to 1.53.0-22.1
cargo1.55 - update to 1.55.0-150300.7.6.1
cargo1.55-debuginfo - update to 1.55.0-150300.7.6.1
rust1.55 - update to 1.55.0-150300.7.6.1
rust1.55-debuginfo - update to 1.55.0-150300.7.6.1
rust1.56-debuginfo - update to 1.56.1-150300.7.6.1
rust1.56 - update to 1.56.1-150300.7.6.1
cargo1.56-debuginfo - update to 1.56.1-150300.7.6.1
cargo1.56 - update to 1.56.1-150300.7.6.1
rust1.57 - update to 1.57.0-150300.7.7.1
cargo1.57 - update to 1.57.0-150300.7.7.1
rust1.57-debuginfo - update to 1.57.0-150300.7.7.1
cargo1.57-debuginfo - update to 1.57.0-150300.7.7.1
rust1.58-debuginfo - update to 1.58.0-150300.7.3.1
rust1.58 - update to 1.58.0-150300.7.3.1
cargo1.58-debuginfo - update to 1.58.0-150300.7.3.1
cargo1.58 - update to 1.58.0-150300.7.3.1
rust-toolset - update to 1.58.1-1
rust-std-static-wasm32-wasi - update to 1.58.1-1
cargo - update to 1.58.1-1
rust-std-static-wasm32-unknown-unknown - update to 1.58.1-1
clippy - update to 1.58.1-1
rls - update to 1.58.1-1
rust - update to 1.58.1-1
rust-analysis - update to 1.58.1-1
rust-doc - update to 1.58.1-1
rust-std-static - update to 1.58.1-1
rustfmt - update to 1.58.1-1
rust-src - update to 1.58.1-1
rust-lldb - update to 1.58.1-1
rust-gdb - update to 1.58.1-1
cargo-doc - update to 1.58.1-1
rust-debugger-common - update to 1.58.1-1
rust - addressed in versions 1.58.1-1.el7, 1.58.1-1.fc34, 1.58.1-1.fc35
rust1.59-debuginfo - update to 1.59.0-150300.7.4.2
rust1.59 - update to 1.59.0-150300.7.4.2
cargo1.59-debuginfo - update to 1.59.0-150300.7.4.2
cargo1.59 - update to 1.59.0-150300.7.4.2
rust-oxipng - addressed in versions 5.0.1-4.fc34, 5.0.1-4.fc35, 5.0.1-4.fc36
rust-afterburn - addressed in versions 5.2.0-3.fc34, 5.2.0-3.fc35, 5.2.0-3.fc36, 5.2.0-4.fc34, 5.2.0-4.fc35
rust-fd-find - addressed in versions 8.2.1-5.fc34, 8.2.1-5.fc35, 8.2.1-5.fc36
watchOS - update to 8.5 19T242
rust-tokei - addressed in versions 12.0.4-11.fc34, 12.0.4-11.fc35, 12.0.4-11.fc36
rust-ripgrep - addressed in versions 13.0.0-4.fc34, 13.0.0-4.fc35, 13.0.0-4.fc36
llvm13 - update to 13.0.1-1.el7
iPadOS - update to 15.4 19E241
Apple iOS - update to 15.4 19E241
tvOS - update to 15.4 19L440

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins