A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.
https://www.openwall.com/lists/oss-security/2022/01/24/4
https://sourceware.org/bugzilla/show_bug.cgi?id=28770
https://security.netapp.com/advisory/ntap-20221020-0003/
https://security-tracker.debian.org/tracker/CVE-2021-3998
https://bugzilla.redhat.com/show_bug.cgi?id=2024633
https://access.redhat.com/security/cve/CVE-2021-3998
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ee8d5e33adb284601c00c94687bc907e10aec9bb
https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=84d2d0fe20bdf94feed82b21b4d7d136db471f03
Source: Mitre, NVD
Published: 2022-08-24
Updated: 2023-02-12
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N
Severity: High
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.00092