CVE-2021-43412

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
07/11/2021
Last modified:
07/11/2023

Description

An issue was discovered in GNU Hurd before 0.9 20210404-9. libports accepts fake notification messages from any client on any port, which can lead to port use-after-free. This can be exploited for local privilege escalation to get full root access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:hurd:*:*:*:*:*:*:*:* 0.9.20210404-9 (excluding)