{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos7els/vex/2021/cve-2021-3982-els_os-centos7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-12T15:35:34Z",
      "generator": {
        "date": "2026-06-12T15:35:34Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2021-3982-ELS_OS-CENTOS7ELS",
      "initial_release_date": "2021-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2021-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-13T09:52:19Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-06-12T15:35:34Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2021-3982"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "gnome-shell-0:3.28.3-34.el7_9.x86_64",
                "product": {
                  "name": "gnome-shell-0:3.28.3-34.el7_9.x86_64",
                  "product_id": "gnome-shell-0:3.28.3-34.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/gnome-shell@3.28.3-34.el7_9?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64",
                  "product_id": "gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/gnome-shell@3.28.3-34.el7_9.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnome-shell-0:3.28.3-34.el7_9.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:gnome-shell-0:3.28.3-34.el7_9.x86_64"
        },
        "product_reference": "gnome-shell-0:3.28.3-34.el7_9.x86_64",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-3982",
      "cwe": {
        "id": "CWE-273",
        "name": "Improper Check for Dropped Privileges"
      },
      "notes": [
        {
          "category": "description",
          "text": "Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other services running in the same machine.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-7:gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64",
          "CentOS-7:gnome-shell-0:3.28.3-34.el7_9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2021-3982"
        },
        {
          "category": "external",
          "summary": "https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/2284",
          "url": "https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/2284"
        },
        {
          "category": "external",
          "summary": "https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/2060",
          "url": "https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/2060"
        }
      ],
      "release_date": "2022-04-29T17:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-06-12T13:07:24.855681Z",
          "details": "Exploitation is local-only and requires a specific configuration where the GNOME Shell binary is granted the CAP_SYS_NICE capability; systems that do not install GNOME Shell or do not assign this capability are not affected. The impact is limited to availability (raising process scheduler priority to cause CPU starvation), with no confidentiality or integrity effect. Given these narrow preconditions and DoS-only outcome, this can be safely deprioritized for enterprise server and VM environments.",
          "product_ids": [
            "CentOS-7:gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64",
            "CentOS-7:gnome-shell-0:3.28.3-34.el7_9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 2.1,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-7:gnome-shell-0:3.28.3-34.el7_9.tuxcare.els1.x86_64",
            "CentOS-7:gnome-shell-0:3.28.3-34.el7_9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}