The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.
CVSS Details
- CVSS 3.1 Base Score: 4.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade systemtap-initscriptUpgrade systemtap-clientUpgrade systemtap-sdt-develUpgrade systemtap-runtimeUpgrade systemtapUpgrade systemtap-testsuiteUpgrade systemtap-server | Dec 1, 2016 | Jul 26, 2012 |
| Debian | — | Upgrade systemtap | Jul 30, 2024 | Jul 26, 2012 |
| Oracle_linux | — | Upgrade systemtap-testsuiteUpgrade systemtap-clientUpgrade systemtapUpgrade systemtap-serverUpgrade systemtap-sdt-develUpgrade systemtap-runtimeUpgrade systemtap-grapherUpgrade systemtap-initscript | Oct 16, 2024 | Jul 26, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 25, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub