SB2024052817 - Race condition in FDUPES
Published: May 28, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2022-48682)
The vulnerability allows a local user to delete arbitrary files.
The vulnerability exists due to a race condition. A local user can delete arbitrary files on the system via a symbolic link.
Remediation
Install update from vendor's website.
References
- https://github.com/adrianlopezroche/fdupes/blob/4b6bcde1b3eb1cebe87cd30814f7d6cf4ee46e95/fdupes.c
- https://github.com/adrianlopezroche/fdupes/commit/85680897148f1ac33b55418e00334116e419717f
- https://bugzilla.suse.com/show_bug.cgi?id=1200381
- https://github.com/adrianlopezroche/fdupes/compare/v2.1.2...v2.2.0