PT-2018-5040 · Dracut+1 · Dracut+1
Andreas Stieger
·
Publicado
2016-11-17
·
Atualizado
2024-06-15
·
CVE-2016-8637
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
dracut versions prior to 045
Description
A local information disclosure issue was found when generating initramfs images with world-readable permissions, particularly when 'early cpio' is used, such as including microcode updates. This allows a local attacker to obtain sensitive information from these files, including encryption keys or credentials.
Recommendations
For dracut versions prior to 045, update to version 045 or later to resolve the issue. As a temporary workaround, consider restricting access to initramfs images generated with 'early cpio' to minimize the risk of exploitation. Avoid using world-readable permissions when generating these images until the issue is resolved.
Exploit
Correção
Information Disclosure
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Suse
Dracut