util-linux是util-linux组织开源的一套操作系统基础工具集。 util-linux 2.41.5及之前版本和2.42.2及之前版本存在异常处理不当漏洞,该漏洞源于在运行挂载后钩子前未检查挂载辅助程序退出状态,导致低权限用户可在挂载辅助程序失败后利用X-mount.idmap或X-mount.owner钩子,克隆具有继承suid位的文件系统或修改目标inode权限,从而实现权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| util-linux | util-linux | 2.39< 2.41.6 |
affected |
2.42< 2.42.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| util-linux | util-linux | 2.39 ~ 2.41.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet