{"id":"UBUNTU-CVE-2021-3996","details":"A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.","modified":"2026-04-22T14:56:19.456278Z","published":"2022-02-01T00:00:00Z","related":["USN-5279-1"],"upstream":["CVE-2021-3996"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3996"},{"type":"REPORT","url":"https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.37/v2.37.3-ReleaseNotes"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2022/01/24/2"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5279-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-3996"}],"affected":[{"package":{"name":"util-linux","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.3?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.34-0.1ubuntu9.3"}]}],"versions":["2.34-0.1ubuntu2","2.34-0.1ubuntu4","2.34-0.1ubuntu5","2.34-0.1ubuntu6","2.34-0.1ubuntu7","2.34-0.1ubuntu8","2.34-0.1ubuntu9","2.34-0.1ubuntu9.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"bsdutils","binary_version":"1:2.34-0.1ubuntu9.3"},{"binary_name":"fdisk","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"libblkid1","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"libfdisk1","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"libmount1","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"libsmartcols1","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"libuuid1","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"mount","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"rfkill","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"util-linux","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"util-linux-locales","binary_version":"2.34-0.1ubuntu9.3"},{"binary_name":"uuid-runtime","binary_version":"2.34-0.1ubuntu9.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3996.json"}},{"package":{"name":"util-linux","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/util-linux@2.37.2-4ubuntu2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.37.2-4ubuntu2"}]}],"versions":["2.36.1-8ubuntu1","2.37.2-4ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.37.2-4ubuntu2","binary_name":"bsdextrautils"},{"binary_version":"1:2.37.2-4ubuntu2","binary_name":"bsdutils"},{"binary_version":"2.37.2-4ubuntu2","binary_name":"eject"},{"binary_version":"2.37.2-4ubuntu2","binary_name":"fdisk"},{"binary_name":"libblkid1","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"libfdisk1","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"libmount1","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"libsmartcols1","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"libuuid1","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"mount","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"rfkill","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"util-linux","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"util-linux-locales","binary_version":"2.37.2-4ubuntu2"},{"binary_name":"uuid-runtime","binary_version":"2.37.2-4ubuntu2"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3996.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}