PT-2024-10822 · Gentoo+1 · Gentoo+1
Michael Orlitzky
·
Published
2024-01-15
·
Updated
2024-01-22
·
CVE-2020-36770
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Slurm versions through 22.05.3
Description
The issue arises from the
pkg postinst in the Gentoo ebuild for Slurm, which unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to become the owner of root-owned files.Recommendations
For Slurm versions through 22.05.3, consider restricting the
slurm user's access to sensitive files until a patch is available. As a temporary workaround, avoid using the pkg postinst script in the Gentoo ebuild for Slurm, or ensure that the chown command is not executed unnecessarily. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gentoo
Slurm