CVE-2021-32550
Linux Ubuntu vulnerability analysis and mitigation

Overview

CVE-2021-32550 is a security vulnerability discovered in the read_file() function within apport/hookutils.py. The vulnerability was identified when this function is used by the openjdk-14 package apport hooks, where it would follow symbolic links or open FIFOs, potentially exposing private data to other local users (NVD, Ubuntu).

Technical details

The vulnerability exists in the read_file() function of apport/hookutils.py, which would incorrectly follow symbolic links and open FIFOs without proper validation. The issue received a CVSS 3.1 Base Score of 5.5 (MEDIUM) from NIST with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, while Canonical Ltd. assessed it with a Base Score of 7.3 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L (NVD).

Impact

When exploited, this vulnerability could allow local users to expose private data through the openjdk-14 package apport hooks. The vulnerability primarily affects the confidentiality of the system, with high impact potential for data exposure (Launchpad Bug).

Exploitability

The vulnerability requires local access and can be exploited when the read_file() function is used by the openjdk-14 package apport hooks. The exploitation involves creating symbolic links to sensitive files that could then be read through the vulnerable function (Launchpad Bug).

Mitigation and workarounds

The vulnerability was patched by updating apport to prevent following symbolic links and ensuring the file isn't a FIFO in read_file(). The fix was implemented across multiple Ubuntu versions including 18.04 LTS, 20.04 LTS, 20.10, and 21.04. The patches were released on May 25, 2021 (Launchpad Bug).

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-50538HIGH8.8
  • Linux Debian logoLinux Debian
  • veyon
NoYesAug 21, 2026
CVE-2026-53525HIGH7.4
  • Linux Debian logoLinux Debian
  • weechat
NoYesAug 21, 2026
CVE-2026-53524MEDIUM6.5
  • Linux Debian logoLinux Debian
  • weechat
NoYesAug 21, 2026
CVE-2026-56136NONEN/A
  • Linux Debian logoLinux Debian
  • libntfs-3g-devel
NoYesAug 24, 2026
CVE-2026-56135NONEN/A
  • Linux Debian logoLinux Debian
  • libntfs-3g87
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management