Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
References
Configurations
History
No history.
Information
Published : 2021-02-08 20:15
Updated : 2024-11-21 05:57
NVD link : CVE-2021-26910
Mitre link : CVE-2021-26910
CVE.ORG link : CVE-2021-26910
JSON object : View
Products Affected
firejail_project
- firejail
debian
- debian_linux
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition