CVE-2017-2616

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
redhatCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
util-linux_projectutil-linux
𝑥
< 2.32.1
debiandebian_linux
8.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_eus
7.3
redhatenterprise_linux_server_eus
7.4
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
coreutils
bullseye
8.32-4
fixed
bookworm
9.1-1
fixed
sid
9.5-1
fixed
trixie
9.5-1
fixed
shadow
bullseye
1:4.8.1-1
fixed
bookworm
1:4.13+dfsg1-1
fixed
sid
1:4.16.0-4
fixed
trixie
1:4.16.0-4
fixed
util-linux
bullseye (security)
2.36.1-8+deb11u2
fixed
bullseye
2.36.1-8+deb11u2
fixed
bookworm
2.38.1-5+deb12u1
fixed
bookworm (security)
2.38.1-5+deb12u1
fixed
trixie
2.40.2-9
fixed
sid
2.40.2-10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
shadow
disco
Fixed 1:4.2-3.2ubuntu2
released
cosmic
Fixed 1:4.2-3.2ubuntu2
released
bionic
Fixed 1:4.2-3.2ubuntu2
released
artful
Fixed 1:4.2-3.2ubuntu2
released
zesty
Fixed 1:4.2-3.2ubuntu1.17.04.1
released
yakkety
Fixed 1:4.2-3.2ubuntu1.16.10.1
released
xenial
Fixed 1:4.2-3.1ubuntu5.2
released
trusty
Fixed 1:4.1.5.1-1ubuntu9.4
released
precise
ignored
util-linux
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
ignored
zesty
ignored
yakkety
ignored
xenial
not-affected
trusty
not-affected
precise
ignored