Insecure temporary files In util-linux
Description
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 2.20.1-1 | ||
debian 12 | 2.20.1-1 | ||
debian 14 | 2.20.1-1 | ||
debian 13 | 2.20.1-1 | ||
rpm rhel5 | 0:2.13-0.59.el5 | ||
rpm rhel6 | 0:2.17.2-12.4.el6 |
Aliases
1. 2. 3. 4. 5.