Permissions, Privileges, and Access Controls in pcs - CVE-2022-2735

 

Permissions, Privileges, and Access Controls in pcs - CVE-2022-2735

Published: September 5, 2022 / Updated: April 7, 2023


Vulnerability identifier: #VU66985
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2022-2735
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect permissions set on a Unix socket used for internal communication between PCS daemons. A local user can obtain the authentication token for hacluster and gain control over the cluster managed by pcs.


Affected software

pcs
Debian Linux
Anolis OS
Ubuntu
openEuler
Fedora
pcs (Ubuntu package)
pcs (Red Hat package)
pcs
pcs-snmp
pcs (Debian package)

How to mitigate CVE-2022-2735

Install update from vendor's website.

pcs - update to 0.11.4
pcs (Ubuntu package) - addressed in versions 0.9.149-1ubuntu1.1+esm1, 0.10.4-3ubuntu0.1~esm1, 0.10.11-2ubuntu3+esm1
pcs (Red Hat package) - addressed in versions 0.10.4-6.el8_2.3, 0.10.8-1.el8_4.2, 0.10.12-6.el8_6.2, 0.11.1-10.el9_0.2
pcs - update to 0.10.5-3
pcs-snmp - update to 0.10.5-3
pcs (Debian package) - update to 0.10.8-1+deb11u1
pcs - update to 0.10.12-6.0.1
pcs-snmp - update to 0.10.12-6.0.1
pcs - update to 0.11.3-4.fc38

External References

Related Security Bulletins