CVE Vulnerabilities

CVE-2017-2616

Privilege Defined With Unsafe Actions

Published: Jul 27, 2018 | Modified: Nov 21, 2024
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.7 MEDIUM
AV:L/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

NameVendorStart VersionEnd Version
Util-linuxUtil-linux_project*2.32.1 (excluding)
Red Hat Enterprise Linux 6RedHatcoreutils-0:8.4-46.el6*
Red Hat Enterprise Linux 7RedHatutil-linux-0:2.23.2-33.el7_3.2*
ShadowUbuntuartful*
ShadowUbuntubionic*
ShadowUbuntucosmic*
ShadowUbuntudevel*
ShadowUbuntudisco*
ShadowUbuntuesm-infra-legacy/trusty*
ShadowUbuntuesm-infra/bionic*
ShadowUbuntuesm-infra/xenial*
ShadowUbuntuprecise*
ShadowUbuntutrusty*
ShadowUbuntutrusty/esm*
ShadowUbuntuupstream*
ShadowUbuntuvivid/stable-phone-overlay*
ShadowUbuntuvivid/ubuntu-core*
ShadowUbuntuxenial*
ShadowUbuntuyakkety*
ShadowUbuntuzesty*
Util-linuxUbuntuartful*
Util-linuxUbuntuprecise*
Util-linuxUbuntutrusty*
Util-linuxUbuntuupstream*
Util-linuxUbuntuvivid/stable-phone-overlay*
Util-linuxUbuntuvivid/ubuntu-core*
Util-linuxUbuntuyakkety*
Util-linuxUbuntuzesty*

Potential Mitigations

References