systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade systemd | Apr 25, 2019 | Jan 29, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade systemd-sysvUpgrade systemdUpgrade systemd-develUpgrade systemd-libsUpgrade systemd-python | Feb 15, 2019 | Jan 29, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 29, 2018 |
| Suse | — | Upgrade systemd-bash-completionUpgrade systemdUpgrade libudev-develUpgrade systemd-langUpgrade systemd-docUpgrade libudev1Upgrade systemd-containerUpgrade systemd-coredumpUpgrade udevUpgrade libudev1-32bitUpgrade systemd-32bitUpgrade libsystemd0Upgrade systemd-journal-remoteUpgrade systemd-sysvinitUpgrade libsystemd0-32bitUpgrade systemd-devel | Feb 27, 2018 | Jan 29, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 29, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub