A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00081}

epss

{'score': 0.00083}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2022-08-25T00:00:00

Updated: 2024-08-04T00:40:47.458Z

Reserved: 2021-06-29T00:00:00

Link: CVE-2021-35938

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-25T20:15:09.307

Modified: 2024-11-21T06:12:47.313

Link: CVE-2021-35938

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-06-30T00:00:00Z

Links: CVE-2021-35938 - Bugzilla