CVE-2017-2616

EUVD-2017-11777
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
redhatCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
util-linux_projectutil-linux
𝑥
< 2.32.1
debiandebian_linux
8.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_eus
7.3
redhatenterprise_linux_server_eus
7.4
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
coreutils
bookworm
9.1-1
fixed
bullseye
8.32-4
fixed
sid
9.5-1
fixed
trixie
9.5-1
fixed
shadow
bookworm
1:4.13+dfsg1-1
fixed
bullseye
1:4.8.1-1
fixed
sid
1:4.16.0-4
fixed
trixie
1:4.16.0-4
fixed
util-linux
bookworm
2.38.1-5+deb12u1
fixed
bookworm (security)
2.38.1-5+deb12u1
fixed
bullseye
2.36.1-8+deb11u2
fixed
bullseye (security)
2.36.1-8+deb11u2
fixed
sid
2.40.2-10
fixed
trixie
2.40.2-9
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
shadow
artful
Fixed 1:4.2-3.2ubuntu2
released
bionic
Fixed 1:4.2-3.2ubuntu2
released
cosmic
Fixed 1:4.2-3.2ubuntu2
released
disco
Fixed 1:4.2-3.2ubuntu2
released
precise
ignored
trusty
Fixed 1:4.1.5.1-1ubuntu9.4
released
xenial
Fixed 1:4.2-3.1ubuntu5.2
released
yakkety
Fixed 1:4.2-3.2ubuntu1.16.10.1
released
zesty
Fixed 1:4.2-3.2ubuntu1.17.04.1
released
util-linux
artful
ignored
bionic
not-affected
cosmic
not-affected
disco
not-affected
precise
ignored
trusty
not-affected
xenial
not-affected
yakkety
ignored
zesty
ignored