oss-sec mailing list archives
Re: util-linux 2.29.2 fixes CVE-2017-2616
From: Hanno Böck <hanno () hboeck de>
Date: Thu, 23 Feb 2017 10:40:54 +0100
Hi, On Thu, 23 Feb 2017 08:46:30 +0100 Marcus Meissner <meissner () suse de> wrote:
util-linux 2.29.2 fixes CVE-2017-2616, a race condition which allowed local users to kill other processes.
I just reported this in Gentoo [1], yet I was informed that we're not using su from util-linux, but from shadow. So depending on the distribution you may not use this implementation of su. I haven't digged deeper into this, can you say if this issue is generic enough to be expected in other implementations as well? (Not sure if the implementations of su in shadow and util-linux share a common codebase, seems to be quite old stuff.) [1] https://bugs.gentoo.org/show_bug.cgi?id=610664 -- Hanno Böck https://hboeck.de/ mail/jabber: hanno () hboeck de GPG: FE73757FA60E4E21B937579FA5880072BBB51E42
Current thread:
- util-linux 2.29.2 fixes CVE-2017-2616 Marcus Meissner (Feb 22)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Hanno Böck (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Marcus Meissner (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Assaf Gordon (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Hanno Böck (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Bálint Réczey (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Emilio Pozuelo Monfort (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Serge E. Hallyn (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Leo Famulari (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Tobias Stöckmann (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Marcus Meissner (Feb 23)
- Re: util-linux 2.29.2 fixes CVE-2017-2616 Hanno Böck (Feb 23)