UNIX symbolic link following in cups - CVE-2024-35235
Published: June 13, 2024 / Updated: February 7, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue. A local user can create a specially crafted symbolic link to a critical file on the system and make it world-writable.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
IBM Process Mining
Cryostat
Migration Toolkit for Runtimes
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
Oracle Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Desktop Applications Module
Development Tools Module
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
RecoverPoint for Virtual Machines
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cups (Ubuntu package)
cups-libs-debuginfo
cups-debugsource
cups-libs-debuginfo-32bit
cups-libs-32bit
cups-libs
cups-client
cups
cups-client-debuginfo
cups-ddk
cups-debuginfo
cups-devel
cups-ddk-debuginfo
cups (Red Hat package)
cups-filesystem
cups-doc
cups-lpd
cups-ipptool
libcups2-debuginfo
libcups2
cups-config
libcupsmime1
libcups2-32bit-debuginfo
libcupsmime1-32bit
libcupsppdc1-debuginfo
libcupscgi1
libcupscgi1-debuginfo
libcupsppdc1
libcupsimage2
libcupsmime1-debuginfo
libcupsimage2-debuginfo
cups-devel-32bit
libcupscgi1-32bit
libcupsimage2-32bit-debuginfo
libcupsppdc1-32bit
libcupsppdc1-32bit-debuginfo
libcupsimage2-32bit
libcupsmime1-32bit-debuginfo
libcups2-32bit
libcupscgi1-32bit-debuginfo
cups-help
cups-printerapp
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
watsonx Assistant for IBM Cloud Pak for Data
Storage Resource Manager
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
EMC Cloud Tiering Appliance
Business Automation Insights
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
How to mitigate CVE-2024-35235
IBM Process Mining - update to 1.15.0 IF002
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
cups (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.1-9ubuntu1.7, 2.4.1op1-1ubuntu4.9, 2.4.6-0ubuntu3.1, 2.4.7-1.2ubuntu7.1
Migration Toolkit for Runtimes - update to 1.2.7
OpenShift API for Data Protection (OADP) - update to 1.3.3
cups-libs-debuginfo - update to 1.7.5-20.49.1
cups-debugsource - addressed in versions 1.7.5-20.49.1, 2.2.7-150000.3.59.1
cups-libs-debuginfo-32bit - update to 1.7.5-20.49.1
cups-libs-32bit - update to 1.7.5-20.49.1
cups-libs - update to 1.7.5-20.49.1
cups-client - addressed in versions 1.7.5-20.49.1, 2.2.7-150000.3.59.1
cups - addressed in versions 1.7.5-20.49.1, 2.2.7-150000.3.59.1
cups-client-debuginfo - addressed in versions 1.7.5-20.49.1, 2.2.7-150000.3.59.1
cups-ddk - addressed in versions 1.7.5-20.49.1, 2.2.7-150000.3.59.1
cups-debuginfo - addressed in versions 1.7.5-20.49.1, 2.2.7-150000.3.59.1
cups-devel - addressed in versions 1.7.5-20.49.1, 2.2.7-150000.3.59.1
cups-ddk-debuginfo - addressed in versions 1.7.5-20.49.1, 2.2.7-150000.3.59.1
Migration Toolkit for Containers - update to 1.8.4
cups (Red Hat package) - addressed in versions 2.2.6-45.el8_6.5, 2.2.6-51.el8_8.4
cups - addressed in versions 2.2.6-60.0.1, 2.4.10-1
cups-filesystem - addressed in versions 2.2.6-60.0.1, 2.4.10-1
cups-doc - addressed in versions 2.2.6-60.0.1, 2.4.10-1
cups-lpd - addressed in versions 2.2.6-60.0.1, 2.4.10-1
cups-libs - addressed in versions 2.2.6-60.0.1, 2.4.10-1
cups-ipptool - addressed in versions 2.2.6-60.0.1, 2.4.10-1
cups-devel - addressed in versions 2.2.6-60.0.1, 2.4.10-1
cups-client - addressed in versions 2.2.6-60.0.1, 2.4.10-1
libcups2-debuginfo - update to 2.2.7-150000.3.59.1
libcups2 - update to 2.2.7-150000.3.59.1
cups-config - update to 2.2.7-150000.3.59.1
libcupsmime1 - update to 2.2.7-150000.3.59.1
libcups2-32bit-debuginfo - update to 2.2.7-150000.3.59.1
libcupsmime1-32bit - update to 2.2.7-150000.3.59.1
libcupsppdc1-debuginfo - update to 2.2.7-150000.3.59.1
libcupscgi1 - update to 2.2.7-150000.3.59.1
libcupscgi1-debuginfo - update to 2.2.7-150000.3.59.1
libcupsppdc1 - update to 2.2.7-150000.3.59.1
libcupsimage2 - update to 2.2.7-150000.3.59.1
libcupsmime1-debuginfo - update to 2.2.7-150000.3.59.1
libcupsimage2-debuginfo - update to 2.2.7-150000.3.59.1
cups-devel-32bit - update to 2.2.7-150000.3.59.1
libcupscgi1-32bit - update to 2.2.7-150000.3.59.1
libcupsimage2-32bit-debuginfo - update to 2.2.7-150000.3.59.1
libcupsppdc1-32bit - update to 2.2.7-150000.3.59.1
libcupsppdc1-32bit-debuginfo - update to 2.2.7-150000.3.59.1
libcupsimage2-32bit - update to 2.2.7-150000.3.59.1
libcupsmime1-32bit-debuginfo - update to 2.2.7-150000.3.59.1
libcups2-32bit - update to 2.2.7-150000.3.59.1
libcupscgi1-32bit-debuginfo - update to 2.2.7-150000.3.59.1
cups - update to 2.2.13-20
cups-debuginfo - update to 2.2.13-20
cups-debugsource - update to 2.2.13-20
cups-devel - update to 2.2.13-20
cups-libs - update to 2.2.13-20
cups-help - update to 2.2.13-20
cups - update to 2.4.9
cups-printerapp - update to 2.4.10-1
cups - addressed in versions 2.4.10-1.fc39, 2.4.10-1.fc40
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.63, 4.13.45
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
watsonx Assistant Cartridge - update to 5.1.1
OpenShift Logging - update to 5.6.21
Dell EMC VxRail Appliance - update to 8.0.213
EMC Cloud Tiering Appliance - update to 13.2.0.2.31
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Business Automation Insights - update to 24.0.0.0.1
Links to Public Exploits and PoC-codes
External References
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-vvwp-mv6j-hw6f
- https://github.com/OpenPrinting/cups/commit/ff1f8a623e090dee8a8aadf12a6a4b25efac143d
- https://git.launchpad.net/ubuntu/+source/apparmor/tree/profiles/apparmor.d/abstractions/user-tmp#n21
- https://github.com/OpenPrinting/cups/blob/aba917003c8de55e5bf85010f0ecf1f1ddd1408e/cups/http-addr.c#L229-L240
- http://www.openwall.com/lists/oss-security/2024/06/11/1
- http://www.openwall.com/lists/oss-security/2024/06/12/4
- http://www.openwall.com/lists/oss-security/2024/06/12/5
- https://github.com/OpenPrinting/cups/releases/tag/v2.4.9
Related Security Bulletins
- Privilege escalation in OpenPrinting cupsd
- SUSE update for cups
- SUSE update for cups
- Ubuntu update for cups
- Slackware Linux update for cups
- Fedora 40 update for cups
- Fedora 39 update for cups
- openEuler update for cups
- SUSE update for cups
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Red Hat Enterprise Linux 8 update for cups
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- Red Hat Enterprise Linux 8 update for cups
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in IBM watsonx Assistant for IBM Cloud Pak for Data
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component update for OpenPrinting CUPS
- Anolis OS update for cups
- Anolis OS update for cups
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Dell RecoverPoint for Virtual Machines update for third-party components