PT-2020-15828 · Openzfs · Openzfs
Published
2020-08-27
·
Updated
2020-09-04
·
CVE-2020-24717
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenZFS versions prior to 2.0.0-rc1
Description
The issue misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777, leading to a disruption in access control. This occurs due to a critical flaw in the code added to OpenZFS for FreeBSD support, where group rights are processed as owner rights.
Recommendations
For OpenZFS versions prior to 2.0.0-rc1, update to version 2.0.0-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openzfs