Improper Privilege Management in cifs-utils - CVE-2021-20208

 

Improper Privilege Management in cifs-utils - CVE-2021-20208

Published: June 2, 2022


Vulnerability identifier: #VU63954
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20208
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper privilege management in cifs-utils. A local user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host.


Affected software

cifs-utils
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP
openEuler
Fedora
cifs-utils (Ubuntu package)
cifs-utils-debugsource
cifs-utils-devel
cifs-utils-debuginfo
cifs-utils
cifs-utils-help

How to mitigate CVE-2021-20208

Install updates from vendor's website.

cifs-utils - update to 6.13
cifs-utils (Ubuntu package) - addressed in versions 2:6.0-1ubuntu2+esm1, 2:6.4-1ubuntu1.1+esm1, 2:6.8-1ubuntu1.2, 2:6.9-1ubuntu0.2, 2:6.11-3.1ubuntu0.1, 2:6.14-1ubuntu0.1
cifs-utils-debugsource - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-devel - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-debuginfo - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-debuginfo - update to 6.10-2
cifs-utils-help - update to 6.10-2
cifs-utils-debugsource - update to 6.10-2
cifs-utils-devel - update to 6.10-2
cifs-utils - update to 6.10-2
cifs-utils - addressed in versions 6.13-1.fc33, 6.13-1.fc34, 6.13-1.fc35, 6.13-3.fc33, 6.13-3.fc34, 6.13-3.fc35

External References

Related Security Bulletins