A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.
[
{
"digest": {
"length": 317.0,
"function_hash": "161014158834451860501211053090381499931"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@427215d85e8d1476da1a86b8d67aceb485eb3631",
"deprecated": false,
"id": "CVE-2021-3732-56e34ffd",
"signature_type": "Function",
"target": {
"function": "clone_private_mount",
"file": "fs/namespace.c"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"8999984187058554363278922541838878440",
"119596463303934885792071941850421266046",
"148686281145491656691663855958114056585",
"247567766138460892211856785529722430576",
"32703300237863545256224930219481296098",
"44680479638639440105585747285581580132",
"40426775943179506329924386571502284791",
"163947240875729593087110562909636712163",
"4621223976103922294856767898970871336",
"179398442854192595294123037131333223133",
"199433557158642526275190883997903296502",
"148049604451722858291645882981455981066",
"265687584761250606097267610050509871590",
"127932444701048009989788168086176740468",
"80676845338497063799291306606706880288",
"88963076469193632740681965058926007813",
"263333247430704048294094904158406583572",
"236652358729452587902729307327686057390",
"243214825425620256992343779596970395205",
"60432045311814361887136632416822255033",
"61576180181171176281958525045517728472",
"98222741090416756653647508889457843522",
"164700824244720562455866708282277318937",
"119258988697698457769296765622298402469",
"183002748242863575853139214784377299058",
"321543317769837046784816702796683013855",
"228473480814743993865102267620637855034"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@427215d85e8d1476da1a86b8d67aceb485eb3631",
"deprecated": false,
"id": "CVE-2021-3732-f7978220",
"signature_type": "Line",
"target": {
"file": "fs/namespace.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3732.json"