CVE-2017-2616

Description

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

Risk Information

Base Score
4.7
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.062

Associated Vulnerability

VulnerabilityOS Platform
system login tools (USN-3276-1) login_4.2-3.1ubuntu5.2_i386.debLinux
system login tools (USN-3276-1) login_4.2-3.1ubuntu5.2_amd64.debLinux
system login tools (USN-3276-1) login_4.1.5.1-1ubuntu9.4_i386.debLinux
system login tools (USN-3276-1) login_4.1.5.1-1ubuntu9.4_amd64.debLinux
system login tools (USN-3276-1) login_4.2-3.2ubuntu1.16.10.1_i386.debLinux
system login tools (USN-3276-1) login_4.2-3.2ubuntu1.16.10.1_amd64.debLinux
system login tools (USN-3276-1) login_4.2-3.2ubuntu1.17.04.1_i386.debLinux
system login tools (USN-3276-1) login_4.2-3.2ubuntu1.17.04.1_amd64.debLinux
system login tools (USN-3276-1) passwd_4.2-3.1ubuntu5.2_i386.debLinux
system login tools (USN-3276-1) passwd_4.2-3.1ubuntu5.2_amd64.debLinux
system login tools (USN-3276-1) passwd_4.1.5.1-1ubuntu9.4_i386.debLinux
system login tools (USN-3276-1) passwd_4.1.5.1-1ubuntu9.4_amd64.debLinux
system login tools (USN-3276-1) passwd_4.2-3.2ubuntu1.16.10.1_i386.debLinux
system login tools (USN-3276-1) passwd_4.2-3.2ubuntu1.16.10.1_amd64.debLinux
system login tools (USN-3276-1) passwd_4.2-3.2ubuntu1.17.04.1_i386.debLinux
system login tools (USN-3276-1) passwd_4.2-3.2ubuntu1.17.04.1_amd64.debLinux
system login tools (USN-3276-1) uidmap_4.2-3.1ubuntu5.2_i386.debLinux
system login tools (USN-3276-1) uidmap_4.2-3.1ubuntu5.2_amd64.debLinux
system login tools (USN-3276-1) uidmap_4.1.5.1-1ubuntu9.4_i386.debLinux
system login tools (USN-3276-1) uidmap_4.1.5.1-1ubuntu9.4_amd64.debLinux
system login tools (USN-3276-1) uidmap_4.2-3.2ubuntu1.16.10.1_i386.debLinux
system login tools (USN-3276-1) uidmap_4.2-3.2ubuntu1.16.10.1_amd64.debLinux
system login tools (USN-3276-1) uidmap_4.2-3.2ubuntu1.17.04.1_i386.debLinux
system login tools (USN-3276-1) uidmap_4.2-3.2ubuntu1.17.04.1_amd64.debLinux
(RHSA-2017:0654) Moderate: coreutils security and bug fix update coreutils-8.4-46.el6.i686.rpmLinux
(RHSA-2017:0654) Moderate: coreutils security and bug fix update coreutils-8.4-46.el6.x86_64.rpmLinux
(RHSA-2017:0654) Moderate: coreutils security and bug fix update coreutils-libs-8.4-46.el6.i686.rpmLinux
(RHSA-2017:0654) Moderate: coreutils security and bug fix update coreutils-libs-8.4-46.el6.x86_64.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libblkid-2.23.2-33.el7_3.2.i686.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libblkid-2.23.2-33.el7_3.2.x86_64.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libblkid-devel-2.23.2-33.el7_3.2.i686.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libblkid-devel-2.23.2-33.el7_3.2.x86_64.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libmount-2.23.2-33.el7_3.2.i686.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libmount-2.23.2-33.el7_3.2.x86_64.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libmount-devel-2.23.2-33.el7_3.2.i686.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libmount-devel-2.23.2-33.el7_3.2.x86_64.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libuuid-2.23.2-33.el7_3.2.i686.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libuuid-2.23.2-33.el7_3.2.x86_64.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libuuid-devel-2.23.2-33.el7_3.2.i686.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update libuuid-devel-2.23.2-33.el7_3.2.x86_64.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update util-linux-2.23.2-33.el7_3.2.i686.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update util-linux-2.23.2-33.el7_3.2.x86_64.rpmLinux
(RHSA-2017:0907) Moderate: util-linux security and bug fix update uuidd-2.23.2-33.el7_3.2.x86_64.rpmLinux
SUSE-SU-2018:0866-1(SUSE Linux Enterprise Server 11-SP4 ) coreutils-8.12-6.25.33.3.1.x86_64.rpmLinux
SUSE-SU-2018:0866-1(SUSE Linux Enterprise Server 11-SP4 ) coreutils-lang-8.12-6.25.33.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libblkid1-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libblkid1-32bit-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libblkid1-debuginfo-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libblkid1-debuginfo-32bit-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libfdisk1-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libfdisk1-debuginfo-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libmount1-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libmount1-32bit-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libmount1-debuginfo-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libmount1-debuginfo-32bit-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libsmartcols1-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libsmartcols1-debuginfo-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libuuid-devel-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libuuid1-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libuuid1-32bit-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libuuid1-debuginfo-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) libuuid1-debuginfo-32bit-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libmount-2.28-44.3.3.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libmount-debuginfo-2.28-44.3.3.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libmount-debugsource-2.28-44.3.3.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) util-linux-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) util-linux-debuginfo-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) util-linux-debugsource-2.28-44.3.1.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) util-linux-lang-2.28-44.3.1.noarch.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) util-linux-systemd-2.28-44.3.3.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) util-linux-systemd-debuginfo-2.28-44.3.3.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) util-linux-systemd-debugsource-2.28-44.3.3.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) uuidd-2.28-44.3.3.x86_64.rpmLinux
SUSE-SU-2017:0554-1(SUSE Linux Enterprise Desktop 12-SP2 ) uuidd-debuginfo-2.28-44.3.3.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libblkid1-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libblkid1-32bit-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libblkid1-debuginfo-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libblkid1-debuginfo-32bit-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libmount1-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libmount1-32bit-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libmount1-debuginfo-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libmount1-debuginfo-32bit-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libsmartcols1-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libsmartcols1-debuginfo-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libuuid-devel-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libuuid1-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libuuid1-32bit-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libuuid1-debuginfo-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) libuuid1-debuginfo-32bit-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) python-libmount-2.25-40.2.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) python-libmount-debuginfo-2.25-40.2.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) python-libmount-debugsource-2.25-40.2.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) util-linux-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) util-linux-debuginfo-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) util-linux-debugsource-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) util-linux-lang-2.25-40.1.noarch.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) util-linux-systemd-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) util-linux-systemd-debuginfo-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) util-linux-systemd-debugsource-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) uuidd-2.25-40.1.x86_64.rpmLinux
SUSE-SU-2017:0555-1(SUSE Linux Enterprise Desktop 12-SP1 ) uuidd-debuginfo-2.25-40.1.x86_64.rpmLinux
Coreutils update (ELSA-2017-0654) coreutils-8.4-46.0.1.el6.x86_64.rpmLinux
Coreutils-libs update (ELSA-2017-0654) coreutils-libs-8.4-46.0.1.el6.x86_64.rpmLinux
Coreutils update (ELSA-2017-0654) coreutils-8.4-46.0.1.el6.i686.rpmLinux
Coreutils-libs update (ELSA-2017-0654) coreutils-libs-8.4-46.0.1.el6.i686.rpmLinux
(RHSA-2017:0907)Moderate: security and bug fix update util-linux-debuginfo-2.23.2-33.el7_3.2.i686.rpmLinux
(RHSA-2017:0907)Moderate: security and bug fix update util-linux-debuginfo-2.23.2-33.el7_3.2.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234