Permissions, Privileges, and Access Controls in schroot - CVE-2022-2787
Published: August 18, 2022
Vulnerability identifier: #VU66638
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2787
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to schroot has too permissive rules on chroot or session names. A local user can perform a denial of service on the schroot service for all users that may start a schroot session.
Affected software
schroot
Debian Linux
Gentoo Linux
Ubuntu
schroot (Ubuntu package)
schroot (Debian package)
Debian Linux
Gentoo Linux
Ubuntu
schroot (Ubuntu package)
schroot (Debian package)
How to mitigate CVE-2022-2787
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
schroot (Ubuntu package) - addressed in versions 1.6.10-4ubuntu0.1, 1.6.10-9ubuntu0.1, 1.6.10-12ubuntu3.1
schroot (Debian package) - update to 1.6.10-12+deb11u1
schroot (Debian package) - update to 1.6.10-12+deb11u1