Описание
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the /tmp directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.
Отчет
This Moderate impact flaw in sblim-sfcb allows a local attacker to achieve privileged file corruption or denial of service through a time-of-check-to-time-of-use (TOCTOU) race condition. Exploitation requires a local low-privileged user to win a race during privileged sfcbrepos instance migration, which must be enabled and have specific repository content. The high attack complexity and specific preconditions limit its broader impact.
Меры по смягчению последствий
To mitigate this issue, if instance migration is not required, run the sfcbrepos command with the -i option to disable the vulnerable migration path. For example: sudo sfcbrepos -f -i. Alternatively, avoid running sfcbrepos with elevated privileges on systems where untrusted local users can concurrently write to the /tmp directory. A service restart or reload may be required for changes to take effect if sfcbrepos is managed by a service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | sblim-sfcb | Fix deferred | ||
| Red Hat Enterprise Linux 6 | sblim-sfcb | Out of support scope | ||
| Red Hat Enterprise Linux 7 | sblim-sfcb | Fix deferred | ||
| Red Hat Enterprise Linux 8 | sblim-sfcb | Fix deferred | ||
| Red Hat Enterprise Linux 9 | sblim-sfcb | Fix deferred |
Показывать по
Дополнительная информация
Статус:
6.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.
6.3 Medium
CVSS3