CVE-2018-21269
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2018-21269 affects OpenRC through version 0.42.1. The vulnerability was discovered and disclosed on October 27, 2020. The issue exists in the checkpath functionality of OpenRC, which might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink (NVD).

Technical details

The vulnerability is classified as CWE-59 (Improper Link Resolution Before File Access) with a CVSS v3.1 Base Score of 5.5 MEDIUM (Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) and CVSS v2.0 Base Score of 2.1 LOW (Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) (NVD).

Impact

The vulnerability allows local users to take ownership of arbitrary files on the system by manipulating symlinks in non-terminal path components. This can lead to privilege escalation and unauthorized file ownership changes. For example, an attacker could potentially change the ownership of sensitive files like /etc/passwd (GitHub Issue).

Exploitability

The vulnerability can be exploited by local users who have the ability to create and manipulate symlinks in directories that are processed by OpenRC's checkpath functionality. A proof of concept exists demonstrating how an attacker can exploit the vulnerability by replacing a directory with a symlink to gain ownership of arbitrary files like /etc/passwd (GitHub Issue).

Mitigation and workarounds

Users should upgrade OpenRC to a version newer than 0.42.1 which contains fixes for this vulnerability. Until an upgrade is possible, administrators should carefully review and restrict permissions on directories that are processed by OpenRC's checkpath functionality (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71969HIGH8.4
  • Linux Debian logoLinux Debian
  • optee-os
NoNoAug 10, 2026
CVE-2026-71968HIGH8.4
  • Linux Debian logoLinux Debian
  • optee-os
NoNoAug 10, 2026
CVE-2026-72913HIGH7.3
  • Linux Debian logoLinux Debian
  • kitty
NoYesAug 10, 2026
CVE-2026-73030HIGH7.2
  • Linux Debian logoLinux Debian
  • unearth
NoNoAug 10, 2026
CVE-2026-71967MEDIUM5.7
  • Linux Debian logoLinux Debian
  • optee-os
NoNoAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management