CVE-2017-2616

Published: 22 February 2017

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

Priority

Medium

CVSS 3 base score: 4.7

Status

Package Release Status
shadow
Launchpad, Ubuntu, Debian
Upstream
Released (1:4.4-4)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1:4.2-3.2ubuntu2)
Ubuntu 16.04 LTS (Xenial Xerus)
Released (1:4.2-3.1ubuntu5.2)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (1:4.1.5.1-1ubuntu9.4)
Patches:
Upstream: https://github.com/shadow-maint/shadow/commit/08fd4b69e84364677a10e519ccb25b71710ee686
util-linux
Launchpad, Ubuntu, Debian
Upstream
Released (2.29.2-1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(2.31.1-0.4ubuntu3.3)
Ubuntu 16.04 LTS (Xenial Xerus) Not vulnerable
(binary not built)
Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable
(binary not built)
Patches:
Upstream: https://github.com/karelzak/util-linux/commit/dffab154d29a288aa171ff50263ecc8f2e14a891