CVE-2021-3999

Modified
Published: 24 Aug 2022, 00:00
Last modified:02 Dec 2025, 20:54

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.85% LOW
1% probability -0.17%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

24 Aug 2022, 00:00
Published
Vulnerability first disclosed
02 Dec 2025, 20:54
Last Modified
Vulnerability information updated

Description

A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.85% Percentile: 75%

Techniques & Countermeasures

  • CWE-193Off-by-one Error

    A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Systems

  • debiandebian_linux

    10.0 | 11.0

  • gnuglibc

    < 2.31

  • netappe-series_performance_analyzer

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph700s_firmware

    na

  • netappontap_select_deploy_administration_utility

    na

References (8)