Red Hat released RPM Package Manager updates for Red Hat Enterprise Linux 8 to remediate CVE-2021-35937, CVE-2021-35938, and CVE-2021-35939, three moderate-severity flaws that could allow a local unprivileged attacker to obtain root privileges. The vulnerabilities stem from incomplete unsafe-symlink protections and race conditions during package installation: a TOCTOU condition in symlink checks, races while RPM applies ownership, permissions, or file capabilities, and insufficient validation of intermediary directories in a target path.
The fixes are distributed through advisories including RHSA-2024:0424 for RHEL 8.6 lifecycle and update-service channels, which supplies rpm-4.14.3-26.el8_6, and RHSA-2024:0647 for supported RHEL 8 and Extended Life Cycle 8.10 variants, which supplies rpm-4.14.3-28.el8_9. Affected architectures include x86_64, s390x, ppc64le, and aarch64; Red Hat also issued related fixes for applicable OpenShift and Red Hat OpenShift Data Foundation components. Organizations should apply the appropriate RPM updates and restart applications linked against the RPM library after installation; Red Hat lists no separate qualifying mitigation.

Get the actors, campaigns, and ATT&CK mapping behind it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:0647 for RHEL 8, fixing CVE-2021-35937, CVE-2021-35938, and CVE-2021-35939. The advisory supplied rpm-4.14.3-28.el8_9 and applied to supported RHEL 8 architectures and Extended Life Cycle 8.10 variants.
Red Hat issued RHSA-2024:0582 to fix CVE-2021-35937, CVE-2021-35938, and CVE-2021-35939 for Red Hat Enterprise Linux 8.8 Extended Update Support.
Red Hat issued fixes for CVE-2021-35937, CVE-2021-35938, and CVE-2021-35939 in RHEL 9, RHEL 9.0 EUS, and RHEL 9.2 EUS through RHSA-2024:0463, RHSA-2024:0435, and RHSA-2024:0453, respectively.
Red Hat published RHSA-2024:0424 for RHEL 8.6 lifecycle and update-service channels. The RPM update fixed CVE-2021-35937, CVE-2021-35938, and CVE-2021-35939, supplying RPM version 4.14.3-26.el8_6.
RPM maintainers considered the TOCTOU directory-symlink safety flaw tracked as CVE-2021-35937 fixed in RPM 4.18, which was in alpha during May 2022. The remediation required substantial RPM-internal refactoring rather than a standalone patch.
CVE-2021-35939, an RPM improper-link-resolution flaw stemming from incomplete prior unsafe-symlink protections, was publicly disclosed.
CVE-2021-35938, a symbolic-link race condition in RPM that could permit local privilege escalation, was publicly disclosed.
Red Hat issued RHSA-2024:1477, fixing the three RPM vulnerabilities in OpenShift Container Platform 4.13 windows-machine-config-operator-bundle and windows-machine-config-rhel9-operator components.
Red Hat issued RHSA-2024:1383, fixing the three RPM vulnerabilities in the RHODF-4.15-RHEL-9 cephcsi-rhel9 and mcg-core-rhel9 components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.