CVE-2021-43429
CVE-2021-43429 is a high-severity vulnerability in Seagate Cortx-s3 Server with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-667.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 5.0
- EPSS exploit prediction: 1% (57th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-667
- Affected product: Seagate Cortx-s3 Server
- Published:
- Last modified:
Description
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
Frequently asked questions
- What is CVE-2021-43429?
- A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
- How severe is CVE-2021-43429?
- CVE-2021-43429 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2021-43429 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (57th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-43429?
- CVE-2021-43429 affects Seagate Cortx-s3 Server. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-43429?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2021-43429 published?
- CVE-2021-43429 was published on 2022-04-07 and last updated on 2026-06-17.
References
- https://github.com/Seagate/cortx-s3server/issues/1037
- https://github.com/Seagate/cortx-s3server/pull/1041
Affected products (1)
- cpe:2.3:a:seagate:cortx-s3_server:2021-11-07:*:*:*:*:*:*:*
Other CWE-667 (Improper Locking) vulnerabilities
- CVE-2026-53049 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function…
- CVE-2025-22077 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: Revert "smb: client: fix TCP timers deadlock after…
- CVE-2024-58087 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and…
- CVE-2021-47587 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net: systemport: Add global locking for descriptor…
- CVE-2020-12658 — Critical (CVSS 9.8): gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in…
- CVE-2019-5886 — Critical (CVSS 9.8): An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation…