Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-58302

Опубликовано: 30 июн. 2026
Источник: debian
EPSS Низкий

Описание

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxcncfixed1:2.9.9-1package
linuxcncfixed1:2.9.4-2+deb13u1trixiepackage
linuxcncfixed2.9.0~pre1+git20230208.f1270d6ed7-1+deb12u2bookwormpackage

Примечания

  • https://github.com/LinuxCNC/linuxcnc/commit/00d534c87464a3ed446656998aa02b8abc74b391 (v2.9.9)

EPSS

Процентиль: 5%
0.0015
Низкий

Связанные уязвимости

CVSS3: 8.4
ubuntu
около 1 месяца назад

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.

CVSS3: 8.4
nvd
около 1 месяца назад

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.

CVSS3: 8.4
github
около 1 месяца назад

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.

EPSS

Процентиль: 5%
0.0015
Низкий