PT-2019-14054 · Galliumos · Galliumos

Published

2019-08-22

·

Updated

2020-08-24

·

CVE-2019-15325

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GalliumOS version 3.0
Description The issue arises from the configuration of GalliumOS, where the CONFIG SECURITY YAMA is disabled. However, the /etc/sysctl.d/10-ptrace.conf file attempts to set the /proc/sys/kernel/yama/ptrace scope to 1. This could potentially increase risk due to the misleading appearance of a protection mechanism being in place when, in fact, it is not.
Recommendations For GalliumOS version 3.0, consider enabling CONFIG SECURITY YAMA to ensure the protection mechanism is actually in place, or adjust the /etc/sysctl.d/10-ptrace.conf file to reflect the actual security configuration, avoiding the misleading setting of /proc/sys/kernel/yama/ptrace scope to 1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-15325

Affected Products

Galliumos