Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libcgroup | Jul 30, 2024 | Mar 22, 2011 |
| Oracle_linux | — | Upgrade libcgroupUpgrade libcgroup-pamUpgrade libcgroup-devel | Oct 16, 2024 | Mar 22, 2011 |
| Suse | — | Upgrade libcgroup1Upgrade libcgroup-develUpgrade libcgroup-tools | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libcgroup | Nov 19, 2024 | Mar 22, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub