Back

MEDIUM

binutils: Race window allows users to own arbitrary files

Published Mar 26, 2021

Description

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 26, 2021
Updated Dec 3, 2025
Reserved Dec 17, 2020
CISA Vulnrichment
Updated Dec 3, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 7, 2021
ENISA EUVD
Assigner redhat
Published Mar 26, 2021
Updated Dec 3, 2025
Exploited since n/a
EUVD-2021-7643