CVE-2021-33632 HIGH

CVE-2021-33632: TOCTOU Race Condition problem in iSulad

Vendor Openeuler
Product iSulad
Weakness CWE-367
Published March 25, 2024
Last update August 3, 2024

CVSS base score

7.0/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad/main.C. This issue affects iSulad: 2.0.18-13, from 2.1.4-1 through 2.1.4-2.

Key dates

02Disclosure timeline

March 25, 2024 CVE published
August 3, 2024 Record updated