An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.
Conclusion & alert: CVE-2021-43395 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.03%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-22 | 0.07% | 0.03% | -0.04% |
| 2 | 2025-12-27 | 0.01% | 0.07% | +0.06% |
| 3 | 2025-11-21 | — | 0.01% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| illumos | illumos | < 2022-01-18 | cpe:2.3:o:illumos:illumos:*:*:*:*:*:*:*:* |
| omniosce | omnios | r151038 | cpe:2.3:o:omniosce:omnios:r151038:*:*:*:community:*:*:* |
| openindiana | openindiana | hipster_2021.04 | cpe:2.3:o:openindiana:openindiana:hipster_2021.04:*:*:*:*:*:*:* |
| joyent | smartos | 20210923 | cpe:2.3:o:joyent:smartos:20210923:*:*:*:*:*:*:* |
| oracle | solaris | 10 | cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:* |
| oracle | solaris | 11 | cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.tribblix.org/relnotes.html | Release Notes Third Party Advisory |
| https://github.com/illumos/illumos-gate/blob/069654420de4aade43c63c43cd2896e66945fc8a/usr/src/uts/common/fs/tmpfs/tmp_vnops.c | Exploit Third Party Advisory |
| https://github.com/illumos/illumos-gate/blob/b3403853e80914bd0aade9b5b605da4878078173/usr/src/uts/common/fs/tmpfs/tmp_dir.c | Exploit Third Party Advisory |
| https://github.com/illumos/illumos-gate/commit/f859e7171bb5db34321e45585839c6c3200ebb90 | Patch Third Party Advisory |
| https://illumos.topicbox.com/groups/developer/T1c9e4f27f8c2f959/security-heads-up-illumos14424 | Vendor Advisory |
| https://jgardner100.wordpress.com/2022/01/20/security-heads-up/ | Third Party Advisory |
| https://kebe.com/blog/?p=505 | Third Party Advisory |
| https://www.illumos.org/issues/14424 | Issue Tracking Patch Vendor Advisory |
| https://www.oracle.com/security-alerts/cpujan2022.html | Patch Third Party Advisory |