Vulnerability Description
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Seagate | Cortx-S3 Server | 2021-11-07 |
Related Weaknesses (CWE)
References
- https://github.com/Seagate/cortx-s3server/issues/1037ExploitIssue TrackingThird Party Advisory
- https://github.com/Seagate/cortx-s3server/pull/1041Issue TrackingThird Party Advisory
- https://github.com/Seagate/cortx-s3server/issues/1037ExploitIssue TrackingThird Party Advisory
- https://github.com/Seagate/cortx-s3server/pull/1041Issue TrackingThird Party Advisory
FAQ
What is CVE-2021-43429?
CVE-2021-43429 is a vulnerability with a CVSS score of 7.5 (HIGH). A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
How severe is CVE-2021-43429?
CVE-2021-43429 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43429?
Check the references section above for vendor advisories and patch information. Affected products include: Seagate Cortx-S3 Server.