-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5055-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 24, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : util-linux CVE ID : CVE-2021-3995 CVE-2021-3996 The Qualys Research Labs discovered two vulnerabilities in util-linux's libmount. These flaws allow an unprivileged user to unmount other users' filesystems that are either world-writable themselves or mounted in a world-writable directory (CVE-2021-3996), or to unmount FUSE filesystems that belong to certain other users (CVE-2021-3995). For the stable distribution (bullseye), these problems have been fixed in version 2.36.1-8+deb11u1. We recommend that you upgrade your util-linux packages. For the detailed security status of util-linux please refer to its security tracker page at: https://security-tracker.debian.org/tracker/util-linux Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmHujUNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0TD/BAAmjdIgQgYI0Bc7fcp4tMNHOADXbn5cJysAee0P55kb863q5TM49DzbHuB Xh5Fh7+f4O/rDUXZoW/2hm43pbwDs8EH8LGYjTkspHraRkFEq7mLR6753SIVXHTP U/k9eShfgqRggCq7OTiALBXC00yMNn75PGsd5GPKEv2egSG34+bdp2RPnKc+R7cC yLkwuN6oNq0+KW08HzQp6FSYX7V+a8gsO2QWdlgAuXQC4ICCtYV1jtYn/GJ2SB6E E98nNIUBSR5sf8bXKDpPTrxvbAF1Y0719A7MwGnZS9bNVIBMlx0tNHSCddLrE6/F BMHSyvTQo+xLs5t+Esxb2rfsjuOlrbwte++8GR/LnVr/Zi/vVrzkccwneQlhHPzp Ok8fJ7ipEVbpBWyWdomsQXb8y7o8RFHr9P374JmCQE/urMaOHq1Lc7C9ctVJ5VHb 3+BV/FpMAvY6KekNqriSiX9aXXfWr4HQr7OO6rlz84/rC7wlVpYOx4TRaRGPQPyD STfa8W1shaMlxgL9zgmAtgCu4nNOR4BqVi5ZbuxY8sdbBM7tFD4DuD6sIhNAFadL pIpbvGte7FFHci4vQX/TEZVUGP0yqbNkvuScvT9k9ca/vytJ+9JZf4BUjGF/tO7C HS76o443AhdoYbCm7xtQHf2sm3eqPY6ULXTBZmLgVN3q6jWiyhQ= =lcvO -----END PGP SIGNATURE-----