runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade systemtap | Jul 30, 2024 | Jul 26, 2012 |
| Oracle_linux | — | Upgrade systemtap-clientUpgrade systemtap-sdt-develUpgrade systemtapUpgrade systemtap-testsuiteUpgrade systemtap-initscriptUpgrade systemtap-grapherUpgrade systemtap-runtimeUpgrade systemtap-server | Oct 16, 2024 | Jul 26, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub