CVE-2021-45707
Last modified
CVE-2021-45707 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.. EPSS estimates a 1.64% chance of exploitation in the next 30 days.
Description
An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nix Project | Nix | >= 0.16.0, < 0.20.2 |
| Nix Project | Nix | >= 0.21.0, < 0.21.2 |
| Nix Project | Nix | >= 0.22.0, < 0.22.2 |
References
- https://github.com/advisories/GHSA-wgrg-5h56-jg27Third Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2021-0119.htmlIssue Tracking, Third Party Advisory
- https://github.com/advisories/GHSA-wgrg-5h56-jg27Third Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2021-0119.htmlIssue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-45707?
How severe is CVE-2021-45707?
How do I fix CVE-2021-45707?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-45701An issue was discovered in the tremor-script crate before 0.…9.8
- CVE-2021-45702An issue was discovered in the tremor-script crate before 0.…7.5
- CVE-2021-45703An issue was discovered in the tectonic_xdv crate before 0.1…9.8
- CVE-2021-45704An issue was discovered in the metrics-util crate before 0.7…8.1
- CVE-2021-45705An issue was discovered in the nanorand crate before 0.6.1 f…9.8
- CVE-2021-45706An issue was discovered in the zeroize_derive crate before 1…9.8
- CVE-2021-45708An issue was discovered in the abomonation crate through 202…7.5
- CVE-2021-45709An issue was discovered in the crypto2 crate through 2021-10…9.8
- CVE-2021-45710An issue was discovered in the tokio crate before 1.8.4, and…8.1
- CVE-2021-45711An issue was discovered in the simple_asn1 crate 0.6.0 befor…7.5
- CVE-2021-45712An issue was discovered in the rust-embed crate before 6.3.0…7.5
- CVE-2021-45713An issue was discovered in the rusqlite crate 0.25.x before …7.5
Are you affected by CVE-2021-45707?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
