{"id":"CVE-2021-26910","details":"Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.","modified":"2026-07-08T05:58:59.600283959Z","published":"2021-02-08T20:15:13.090Z","related":["openSUSE-SU-2021:0271-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"https://github.com/netblue30/firejail/releases/tag/0.9.64.4"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/02/msg00015.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202105-19"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4849"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2021/02/09/1"},{"type":"FIX","url":"https://github.com/netblue30/firejail/commit/97d8a03cad19501f017587cc4e47d8418273834b"},{"type":"EVIDENCE","url":"https://unparalleled.eu/blog/2021/20210208-rigged-race-against-firejail-for-local-root/"},{"type":"EVIDENCE","url":"https://unparalleled.eu/publications/2021/advisory-unpar-2021-0.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/netblue30/firejail","events":[{"introduced":"0"},{"fixed":"b818fc40cef9865b3202b7de227348dd26acf9fd"},{"fixed":"97d8a03cad19501f017587cc4e47d8418273834b"}],"database_specific":{"cpe":"cpe:2.3:a:firejail_project:firejail:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.9.64.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.9.64.2","0.9.64","0.9.64rc1","0.9.60","0.9.60-rc1","0.9.58.2","0.9.58","0.9.58-rc1","0.9.56","0.9.56-rc1","0.9.54","0.9.54-rc2","0.9.54-rc1","0.9.52","0.9.50-rc1","0.9.48","0.9.46-rc1","0.9.44","0.9.44-rc1","0.9.42","0.9.42-rc2","0.9.38","0.9.42-rc1","disable-globalcfg","0.9.40","0.9.40-rc1","0.9.38-rc1","0.9.36","0.9.36-rc1","0.9.34","0.9.34-rc1","0.9.32","0.9.32-rc1","0.9.30","0.9.30-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26910.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}