Path traversal in networkd-dispatcher - CVE-2022-29799
Published: April 28, 2022
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in OperationalState or the AdministrativeState. Since the states are used to build the script path, it is possible that a
state would contain directory traversal patterns (e.g. “../../”) to escape from the “/etc/networkd-dispatcher” base directory. A local user can abuse this vulnerability to bypass implemented security restrictions.
Affected software
Ubuntu
networkd-dispatcher (Ubuntu package)
How to mitigate CVE-2022-29799
networkd-dispatcher (Ubuntu package) - addressed in versions 1.7-0ubuntu3.4, 1.7-0ubuntu3.5, 2.1-2ubuntu0.21.10.1, 2.1-2ubuntu0.21.10.2, 2.1-2ubuntu0.22.04.1, 2.1-2ubuntu0.22.04.2, 2.1-2~ubuntu20.04.2, 2.1-2~ubuntu20.04.3