PT-2018-5040 · Dracut+1 · Dracut+1
Andreas Stieger
·
Published
2016-11-17
·
Updated
2024-06-15
·
CVE-2016-8637
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
dracut versions prior to 045
Description
A local information disclosure issue was found when generating initramfs images with world-readable permissions, particularly when 'early cpio' is used, such as including microcode updates. This allows a local attacker to obtain sensitive information from these files, including encryption keys or credentials.
Recommendations
For dracut versions prior to 045, update to version 045 or later to resolve the issue. As a temporary workaround, consider restricting access to initramfs images generated with 'early cpio' to minimize the risk of exploitation. Avoid using world-readable permissions when generating these images until the issue is resolved.
Exploit
Fix
Information Disclosure
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Dracut