A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nano | Sep 26, 2024 | Jun 12, 2024 |
| Amazon Linux Ami 2 | — | Upgrade nano-debuginfoUpgrade nano | Jul 23, 2024 | Jun 12, 2024 |
| Amazon_linux_2023 | — | Upgrade nano-debuginfoUpgrade nano-debugsourceUpgrade nanoUpgrade default-editorUpgrade nano-default-editor | Feb 17, 2025 | Apr 28, 2024 |
| Debian | — | Upgrade nano | Jun 18, 2024 | Jun 12, 2024 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Feb 17, 2025 |
| Oracle_linux | — | Upgrade nano | Oct 16, 2024 | Apr 28, 2024 |
| Redhat_linux | — | Upgrade nanoNo solution existsUpgrade nano-debuginfoUpgrade nano-debugsource | Sep 25, 2024 | Jun 12, 2024 |
| Rocky_linux | — | Upgrade nanoUpgrade nano-debuginfoUpgrade nano-debugsource | Oct 2, 2024 | Jun 12, 2024 |
| Suse | — | Upgrade nano-langUpgrade nano | Jun 12, 2024 | Jun 12, 2024 |
| Ubuntu | — | Upgrade nanoUpgrade nano (Ubuntu Pro) | Oct 17, 2024 | Jun 12, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub