{"id":"CVE-2021-41072","details":"squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.","modified":"2026-07-09T05:45:02.685462Z","published":"2021-09-14T01:15:07.747Z","related":["ALSA-2024:2396","ALSA-2024:3139","SUSE-SU-2023:4424-1","SUSE-SU-2023:4591-1","SUSE-SU-2024:2463-1","openSUSE-SU-2024:11986-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"},{"introduced":"11.0"},{"last_affected":"11.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/10/msg00017.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202305-29"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4987"},{"type":"FIX","url":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd"},{"type":"EVIDENCE","url":"https://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/plougher/squashfs-tools","events":[{"introduced":"0496d7c3de3e09da37ba492081c86159806ebb07"},{"last_affected":"0496d7c3de3e09da37ba492081c86159806ebb07"},{"fixed":"e0485802ec72996c20026da320650d8362f555bd"}],"database_specific":{"extracted_events":[{"introduced":"4.5"},{"last_affected":"4.5"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:squashfs-tools_project:squashfs-tools:4.5:*:*:*:*:*:*:*"}}],"versions":["4.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41072.json","vanir_signatures_modified":"2026-07-09T05:45:02Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-4.c"},"deprecated":false,"digest":{"line_hashes":["13826501275751200352062856063484710912","310321498175082041215183790365799830598","222252199053251366417172446049972134779"],"threshold":0.9},"id":"CVE-2021-41072-17bef277","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-2.c","function":"squashfs_opendir"},"deprecated":false,"digest":{"length":2732,"function_hash":"18901525040218552686384788208234690139"},"id":"CVE-2021-41072-17d236ac","signature_type":"Function"},{"id":"CVE-2021-41072-517a38af","signature_type":"Function","signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-2.c","function":"read_super_2"},"deprecated":false,"digest":{"length":1204,"function_hash":"54792938322389362071123182180987984409"}},{"signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-1.c","function":"squashfs_opendir"},"deprecated":false,"digest":{"function_hash":"18901525040218552686384788208234690139","length":2732},"id":"CVE-2021-41072-8756ee07","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquashfs.h"},"deprecated":false,"digest":{"line_hashes":["89582843057714310302560616203867031271","49499559178388147018567964199199003077"],"threshold":0.9},"id":"CVE-2021-41072-930e8cbd","signature_type":"Line"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-3.c","function":"squashfs_opendir"},"deprecated":false,"digest":{"function_hash":"310221983440334615105753322885496648658","length":2736},"id":"CVE-2021-41072-a593c95f"},{"deprecated":false,"digest":{"line_hashes":["321819792665477290116542811770824633115","153109692933111748050391633369134751289","200445461191816545489245548579996642577","109435949105249211745989750370743912367","13826501275751200352062856063484710912","310321498175082041215183790365799830598","222252199053251366417172446049972134779","48309106085847685141102099689057574146","301385753643948902204006603759959075192","126113801197783751144936314844357774461","184633766433689322390316538862612286887"],"threshold":0.9},"id":"CVE-2021-41072-bde9ce70","signature_type":"Line","signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-2.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-4.c","function":"squashfs_opendir"},"deprecated":false,"digest":{"length":2502,"function_hash":"95133666285201796399228902473090162087"},"id":"CVE-2021-41072-c792fca3"},{"signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-3.c"},"deprecated":false,"digest":{"line_hashes":["13826501275751200352062856063484710912","310321498175082041215183790365799830598","222252199053251366417172446049972134779"],"threshold":0.9},"id":"CVE-2021-41072-e1b69ee7","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bd","target":{"file":"squashfs-tools/unsquash-1.c"},"deprecated":false,"digest":{"line_hashes":["13826501275751200352062856063484710912","310321498175082041215183790365799830598","222252199053251366417172446049972134779"],"threshold":0.9},"id":"CVE-2021-41072-e8094c28","signature_type":"Line"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}]}