Security Advisory

CVE-2017-18078

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-01-29 05:00:00
Last updated 2024-08-05 21:13:47
Assigner mitre
State PUBLISHED

Description

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.