Описание
When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.
Отчет
Affected versions: util-linux v2.17 through v2.43-devel.
Меры по смягчению последствий
Fixed in v2.41.5 and v2.42.2. For restricted user mounts, reject target paths where any ancestor directory is writable by the calling user. Verify the complete ancestor chain integrity before executing the mount syscall.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | util-linux | Affected | ||
| Red Hat Enterprise Linux 7 | util-linux | Affected | ||
| Red Hat Enterprise Linux 8 | util-linux | Affected | ||
| Red Hat Enterprise Linux 9 | rhel8/flatpak-runtime | Affected | ||
| Red Hat Enterprise Linux 9 | rhel8/flatpak-sdk | Affected | ||
| Red Hat Enterprise Linux 9 | util-linux | Affected | ||
| Red Hat Hardened Images | util-linux | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected |
Показывать по
Дополнительная информация
Статус:
7 High
CVSS3
Связанные уязвимости
[Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection]
Уязвимость пакета служебных утилит командной строки Util-linux, связанная с недостаточной проверкой состояния совместно используемого ресурса, позволяющая нарушителю вызвать отказ в обслуживании
7 High
CVSS3