关键信息 CVE Identifier: CVE-2021-3864 Severity: Moderate CVSS v3 Score: 7 Public Date: October 20, 2021 Last Modified: October 8, 2025 Description A flaw was found in how the dumpable flag was handled for certain SUID binaries. This could lead to an unprivileged local user with an eligible root SUID binary being able to exploit this flaw to place core dumps into root-owned directories, potentially resulting in privilege escalation. Affected Packages Red Hat Enterprise Linux 6: Not affected Red Hat Enterprise Linux 7: Moderate impact for kernel and kernel-rt Red Hat Enterprise Linux 8: Not affected Red Hat Enterprise Linux 9: Not affected Mitigation Change the core_pattern default settings to use absolute pathnames. When using ABRT, set MakeCompatCore to "no" in the CCpp.conf file. CVSS v3 Score Breakdown Attack Vector: Local Attack Complexity: High Privileges Required: Low User Interaction: None Scope: Unchanged Confidentiality Impact: High Integrity Impact: High Availability Impact: High