Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

update: libcap #1652

Closed
dongsupark opened this issue Feb 18, 2025 · 0 comments · Fixed by flatcar/scripts#2682
Closed

update: libcap #1652

dongsupark opened this issue Feb 18, 2025 · 0 comments · Fixed by flatcar/scripts#2682
Labels
advisory security advisory cvss/MEDIUM >= 4 && < 7 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

Name: libcap
CVEs: CVE-2025-1390
CVSSs: 6.1
Action Needed: TBD

Summary: The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

See also https://bugzilla.redhat.com/show_bug.cgi?id=2346212, https://bugzilla.openanolis.cn/show_bug.cgi?id=18804.

refmap.gentoo: TBD

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
advisory security advisory cvss/MEDIUM >= 4 && < 7 assessed CVSS security security concerns
Projects
Development

Successfully merging a pull request may close this issue.

1 participant