CVE-2022-1348 - CVE House
Back to Database
Status published Unknown CVE-2022-1348

A vulnerability was found in logrotate in how the state...

Vulnerability Description

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1348

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

logrotate
Vulnerable Versions:
logrotate versions before 3.20.0

Timeline

Official Publish: May 25th, 2022
Last Modified: June 9th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)