A race condition was found in util-linux before 2.32.1 in...
Vulnerability Description
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-2616
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2616
- http://www.securityfocus.com/bid/96404
- https://access.redhat.com/errata/RHSA-2017:0907
- http://rhn.redhat.com/errata/RHSA-2017-0654.html
- https://security.gentoo.org/glsa/201706-02
- https://www.debian.org/security/2017/dsa-3793
- https://github.com/karelzak/util-linux/commit/dffab154d29a288aa171ff50263ecc8f2e14a891
- http://www.securitytracker.com/id/1038271
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.