« List of all CVEs

CVE-2017-18078

Published: 1/29/2018 Last updated: 8/5/2024 Reserved: 1/28/2018

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (2)

conf-libudev ocaml-systemd

Products affected (1)

Product Vendor Version
n/a n/a < 10.0.17763.4252

References (18)