#VU50841 Race condition in Zstandard
Published: February 22, 2021 / Updated: March 4, 2021
Zstandard
Facebook Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition when creating files. The application creates a files with the default umask before chmod'ing to down to 0600. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.