Back

HIGH

kernel: FUSE allows UAF reads of write() buffers, allowing theft of (partial) /etc/shadow hashes

Published Mar 18, 2022

Description

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

Affected products

Remediation

Red Hat statement

For the Red Hat Enterprise Linux the issue actual if fuse or fuse3 package is installed on the system and only privileged user can install it.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 18, 2022
Updated Aug 2, 2024
Reserved Mar 17, 2022
NVD
Status Analyzed
Modified Aug 26, 2026
Red Hat
Severity Moderate
Public date Mar 7, 2022