CVE-2017-2616
—CVSS 3.0
4.7 medium
EPSS
<1%p20
Published
()
Modified
Description
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
- Vendors
- util-linux projectdebianredhat
- Products
- util-linux, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation
- Weakness
- CWE-267, CWE-362
- Vector
- CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.