CVE-2017-18078
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- systemd project/systemd · debian/debian linux · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2018-02/msg00109.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/146184/systemd-Local-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2018/01/29/3Exploit, Mailing List, Third Party Advisory
- https://github.com/systemd/systemd/issues/7736Exploit, Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/04/msg00022.htmlMailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/43935/Exploit, Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2018/01/29/4Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2018-02/msg00109.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/146184/systemd-Local-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2018/01/29/3Exploit, Mailing List, Third Party Advisory
- https://github.com/systemd/systemd/issues/7736Exploit, Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/04/msg00022.htmlMailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/43935/Exploit, Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2018/01/29/4Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.