PT-2018-5040 · Dracut+1 · Dracut+1

Andreas Stieger

·

Publicado

2016-11-17

·

Atualizado

2024-06-15

·

CVE-2016-8637

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dracut versions prior to 045
Description A local information disclosure issue was found when generating initramfs images with world-readable permissions, particularly when 'early cpio' is used, such as including microcode updates. This allows a local attacker to obtain sensitive information from these files, including encryption keys or credentials.
Recommendations For dracut versions prior to 045, update to version 045 or later to resolve the issue. As a temporary workaround, consider restricting access to initramfs images generated with 'early cpio' to minimize the risk of exploitation. Avoid using world-readable permissions when generating these images until the issue is resolved.

Exploit

Correção

Information Disclosure

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8637
MGASA-2016-0387
OPENSUSE-SU-2024:10225-1
SUSE-SU-2017:0641-1
SUSE-SU-2017:0951-1
SUSE-SU-2017:2696-1
SUSE-SU-2017_0641-1
SUSE-SU-2017_0951-1
SUSE-SU-2017_2696-1

Produtos afetados

Suse
Dracut