A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.
CVSS Details
- CVSS 3.1 Base Score: 6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade chrony | Mar 26, 2024 | Aug 24, 2020 |
| Amazon Linux Ami 2 | — | Upgrade chronyUpgrade chrony-debuginfo | Jan 8, 2021 | Aug 24, 2020 |
| Amazon_linux | — | Upgrade chrony | Sep 5, 2020 | Aug 6, 2020 |
| Debian | — | Upgrade chrony | Jul 30, 2024 | Aug 24, 2020 |
| Freebsd | — | Upgrade chrony | Aug 23, 2020 | Aug 22, 2020 |
| Gentoo Linux | — | Upgrade net-misc/chrony. | Aug 31, 2020 | Aug 24, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade chrony | Feb 3, 2021 | Aug 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade chrony | Dec 15, 2020 | Aug 24, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade chrony | Dec 1, 2020 | Aug 24, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 24, 2020 |
| Suse | — | Upgrade chrony-pool-openSUSEUpgrade chrony-pool-suseUpgrade chronyUpgrade chrony-pool-empty | Dec 23, 2021 | Aug 6, 2020 |
| Ubuntu | — | Upgrade chrony | Aug 28, 2020 | Aug 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub