CVE-2021-32773
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-32773 is a security vulnerability discovered in Racket, a general-purpose programming language, affecting versions prior to 8.2. The vulnerability was disclosed on July 19, 2021. It involves a confused deputy attack in the sandbox module resolution system that could allow attackers to manipulate system module dependencies (Racket Advisory).

Technical details

The vulnerability allows code evaluated using the Racket sandbox to cause system modules to incorrectly use attacker-created modules instead of their intended dependencies. This could enable attackers to control system functions and gain access to facilities that were meant to be restricted. The issue specifically relates to the sandbox module resolution system's handling of dependencies (Racket Advisory).

Impact

The vulnerability could allow attackers to bypass security restrictions in the Racket sandbox environment and gain unauthorized access to restricted facilities. This is particularly concerning for multi-user evaluation systems, such as the handin-server system, where the impact could affect multiple users (Racket Advisory).

Mitigation and workarounds

The vulnerability was patched in Racket version 8.2. For systems unable to upgrade immediately, external sandboxing such as containers can limit the impact. The Handin server now provides an API to restrict requires for teaching languages, which can prevent exploitation of this bug. Users are strongly encouraged to use this API. For multi-user evaluation systems, upgrading to version 8.2 or later is required as there are no effective workarounds (Racket Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management