---
title: "CVE-2021-20197\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2021-20197?format=md
keywords: index, follow
---

# CVE-2021-20197

Publication date 26 March 2021

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2021-20197?format=md#impact-score)

Toggle side navigation

## Description

There is an open race window when writing output in the following utilities
in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When
these utilities are run as a privileged user (presumably as part of a
script updating binaries across different users), an unprivileged user can
trick these utilities into getting ownership of arbitrary files through a
symlink.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2021-20197?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| binutils | 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Ignored |
| 18.04 LTS bionic | Ignored |
| 16.04 LTS xenial | Ignored end of standard support, was needs-triage |
| 14.04 LTS trusty | Ignored end of standard support |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2021-20197?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

commits below are from 2.36 branch. At some point, commits were
reverted and then reinstated later on. The list below doesn't
include the added and reverted commits.
These changes are quite intrusive to backport, are regression-
prone and may introduce regressions in other packages. For this
reason we will not be fixing this issue in stable releases.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| binutils | * Upstream:   <https://sourceware.org/git?p=binutils-gdb.git;a=commit;h=365f5fb6d0f0da83817431a275e99e6f6babbe04> * Upstream:   <https://sourceware.org/git?p=binutils-gdb.git;a=commit;h=1a1c3b4cc17687091cff5a368bd6f13742bcfdf8> * Upstream:   <https://sourceware.org/git?p=binutils-gdb.git;a=commit;h=8e03235147a9e774d3ba084e93c2da1aa94d1cec> * Upstream:   <https://sourceware.org/git?p=binutils-gdb.git;a=commit;h=d3edaa91d4cf7202ec14342410194841e2f67f12> * Upstream:   <https://sourceware.org/git?p=binutils-gdb.git;a=commit;h=8b69e61d4be276bb862698aaafddc3e779d23c8f> * Upstream:   <https://sourceware.org/git?p=binutils-gdb.git;a=commit;h=08bdb5f4f98b6a5e1a9bdc89e7d1889933859caf> * Upstream:   <https://sourceware.org/git?p=binutils-gdb.git;a=commit;h=1aad0a424af288cbd7f70ad5f932664a1abd5a79> * Upstream:   <https://sourceware.org/git?p=binutils-gdb.git;a=commit;h=e4454ee18960b092ba10e43100d43fef12f65b26> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | High |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20197)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-20197)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2021-20197)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2021-20197)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2021-20197>
