The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nfs-utils | Linux-nfs | * | 1.3.0-34.18.1 (including) |
Nfs-utils | Ubuntu | bionic | * |
Nfs-utils | Ubuntu | devel | * |
Nfs-utils | Ubuntu | disco | * |
Nfs-utils | Ubuntu | eoan | * |
Nfs-utils | Ubuntu | esm-infra-legacy/trusty | * |
Nfs-utils | Ubuntu | focal | * |
Nfs-utils | Ubuntu | groovy | * |
Nfs-utils | Ubuntu | hirsute | * |
Nfs-utils | Ubuntu | impish | * |
Nfs-utils | Ubuntu | jammy | * |
Nfs-utils | Ubuntu | kinetic | * |
Nfs-utils | Ubuntu | lunar | * |
Nfs-utils | Ubuntu | mantic | * |
Nfs-utils | Ubuntu | noble | * |
Nfs-utils | Ubuntu | oracular | * |
Nfs-utils | Ubuntu | precise/esm | * |
Nfs-utils | Ubuntu | trusty | * |
Nfs-utils | Ubuntu | trusty/esm | * |
Nfs-utils | Ubuntu | upstream | * |
Nfs-utils | Ubuntu | xenial | * |