Description
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | =12.0.0+dfsg-0+deb13u1 || =12.0.0+dfsg-1 || =12.0.0~a6+dfsg-1 || =12.0.0~b1+dfsg-1 || =12.0.0~b2+dfsg-1 || =12.0.0~b3+dfsg-1 || =12.0.0~b5+dfsg-0+deb13u1 || =12.0.0~b5+dfsg-1 || =12.2.0+dfsg-1 || =13.1.0+dfsg-1 || =13.4.0+dfsg-1 || =14.0.0+dfsg-1 || =14.0.0~a4+dfsg-1 |
 debian 14 | | =12.0.0+dfsg-1 || =12.0.0~a6+dfsg-1 || =12.0.0~b1+dfsg-1 || =12.0.0~b2+dfsg-1 || =12.0.0~b3+dfsg-1 || =12.0.0~b5+dfsg-1 || =12.2.0+dfsg-1 || =13.1.0+dfsg-1 || =13.4.0+dfsg-1 || =14.0.0+dfsg-1 || =14.0.0~a4+dfsg-1 |
 rpm rhel8 | | - |
 debian 12 | | =10.0.0+dfsg-1 || =10.0.1+dfsg-1 || =10.1.0+dfsg-1 || =10.5.0+dfsg-1 || =10.5.0+dfsg-2 || =10.6.0+dfsg-1 || =11.1.0+dfsg-1 || =11.2.0+dfsg-1 || =12.0.0+dfsg-1 || =12.0.0~a1+dfsg-1 || =12.0.0~a2+dfsg-1 || =12.0.0~a4+dfsg-1 || =12.0.0~a6+dfsg-1 || =12.0.0~b1+dfsg-1 || =12.0.0~b2+dfsg-1 || =12.0.0~b3+dfsg-1 || =12.0.0~b5+dfsg-1 || =12.2.0+dfsg-1 || =13.1.0+dfsg-1 || =13.4.0+dfsg-1 || =14.0.0+dfsg-1 || =14.0.0~a4+dfsg-1 || =7.3.0+dfsg-1 || =7.7.0+dfsg-1 || =7.7.0+dfsg-2 || =7.7.0+dfsg-3 || =7.7.0+dfsg-3+deb12u1 || =9.4.0+dfsg-1 || =9.5.1+dfsg-1 |
 rpm rhel10 | | - |
 rpm rhel9 | | - |