Описание
A flaw was found in policycoreutils through 3.10 in seunshares. Missing authorization lets a local user in an unconfined SELinux context terminate other processes that are also unconfined, including root-owned ones. That can cause denial of service by killing critical processes.
Отчет
policycoreutils seunshares is vulnerable to missing authorization checks. A local low-privileged user running unconfined may kill other unconfined processes, including root-owned ones, causing denial of service. Affects policycoreutils through 3.10. Default confined SELinux setups reduce the practical attack surface.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | policycoreutils | Under investigation | ||
| Red Hat Enterprise Linux 6 | policycoreutils | Out of support scope | ||
| Red Hat Enterprise Linux 7 | policycoreutils | Under investigation | ||
| Red Hat Enterprise Linux 8 | policycoreutils | Under investigation | ||
| Red Hat Enterprise Linux 9 | policycoreutils | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Hardened Images | policycoreutils-main-3.11-2.1.hum1 | Fixed | RHSA-2026:44343 | 23.07.2026 |
Показывать по
Дополнительная информация
Статус:
5.5 Medium
CVSS3
Связанные уязвимости
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
A Missing Authorization vulnerability in selinux policycoreutils seuns ...
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
5.5 Medium
CVSS3