CVE Vulnerabilities

CVE-2017-2616

Privilege Defined With Unsafe Actions

Published: Jul 27, 2018 | Modified: Nov 21, 2024
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.7 MEDIUM
AV:L/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

Name Vendor Start Version End Version
Util-linux Util-linux_project * 2.32.1 (excluding)
Red Hat Enterprise Linux 6 RedHat coreutils-0:8.4-46.el6 *
Red Hat Enterprise Linux 7 RedHat util-linux-0:2.23.2-33.el7_3.2 *
Shadow Ubuntu artful *
Shadow Ubuntu bionic *
Shadow Ubuntu cosmic *
Shadow Ubuntu devel *
Shadow Ubuntu disco *
Shadow Ubuntu precise *
Shadow Ubuntu trusty *
Shadow Ubuntu upstream *
Shadow Ubuntu vivid/stable-phone-overlay *
Shadow Ubuntu vivid/ubuntu-core *
Shadow Ubuntu xenial *
Shadow Ubuntu yakkety *
Shadow Ubuntu zesty *
Util-linux Ubuntu artful *
Util-linux Ubuntu precise *
Util-linux Ubuntu trusty *
Util-linux Ubuntu upstream *
Util-linux Ubuntu vivid/stable-phone-overlay *
Util-linux Ubuntu vivid/ubuntu-core *
Util-linux Ubuntu yakkety *
Util-linux Ubuntu zesty *

Potential Mitigations

References