PublicDateAtUSN: 2017-02-22 Candidate: CVE-2017-2616 PublicDate: 2018-07-27 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2616 https://ubuntu.com/security/notices/USN-3276-1 https://ubuntu.com/security/notices/USN-3276-3 Description: A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions. Ubuntu-Description: Notes: sbeattie> ubuntu uses su from shadow package, not util-linux up until sbeattie> (2.32-0.2) Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855943 Priority: medium Discovered-by: Tobias Stöckmann Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H [4.7 MEDIUM] Patches_util-linux: upstream: https://github.com/karelzak/util-linux/commit/dffab154d29a288aa171ff50263ecc8f2e14a891 Priority_util-linux: negligible upstream_util-linux: released (2.29.2-1) precise_util-linux: ignored (reached end-of-life) precise/esm_util-linux: not-affected (binary not built) trusty_util-linux: ignored (reached end-of-life) trusty/esm_util-linux: not-affected (binary not built) vivid/stable-phone-overlay_util-linux: ignored (reached end-of-life) vivid/ubuntu-core_util-linux: ignored (reached end-of-life) xenial_util-linux: not-affected (binary not built) esm-infra/xenial_util-linux: not-affected (binary not built) yakkety_util-linux: ignored (reached end-of-life) zesty_util-linux: ignored (reached end-of-life) artful_util-linux: ignored (reached end-of-life) bionic_util-linux: not-affected (2.31.1-0.4ubuntu3.3) cosmic_util-linux: not-affected (2.31.1-0.4ubuntu3.3) disco_util-linux: not-affected (2.31.1-0.4ubuntu3.3) devel_util-linux: not-affected (2.31.1-0.4ubuntu3.3) Patches_shadow: upstream: https://github.com/shadow-maint/shadow/commit/08fd4b69e84364677a10e519ccb25b71710ee686 upstream_shadow: released (1:4.4-4) precise_shadow: ignored (reached end-of-life) precise/esm_shadow: released (1:4.1.4.2+svn3283-3ubuntu5.2) trusty_shadow: released (1:4.1.5.1-1ubuntu9.4) trusty/esm_shadow: released (1:4.1.5.1-1ubuntu9.4) vivid/stable-phone-overlay_shadow: ignored (reached end-of-life) vivid/ubuntu-core_shadow: ignored (reached end-of-life) xenial_shadow: released (1:4.2-3.1ubuntu5.2) esm-infra/xenial_shadow: released (1:4.2-3.1ubuntu5.2) yakkety_shadow: released (1:4.2-3.2ubuntu1.16.10.1) zesty_shadow: released (1:4.2-3.2ubuntu1.17.04.1) artful_shadow: released (1:4.2-3.2ubuntu2) bionic_shadow: released (1:4.2-3.2ubuntu2) cosmic_shadow: released (1:4.2-3.2ubuntu2) disco_shadow: released (1:4.2-3.2ubuntu2) devel_shadow: released (1:4.2-3.2ubuntu2)