It was found that the module-setup.sh script provided by kexec-tools created temporary files in an insecure way. A malicious, local user could use this flaw to conduct a symbolic link attack, allowing them to overwrite the contents of arbitrary files.
DescriptionVasyl Kaigorodov
2015-02-11 14:24:21 UTC
Harald Hoyer from Red Hat reported that /usr/lib/dracut/modules.d/99kdumpbase/module-setup.sh script uses insecure temporary files names, which can lead to a persistent local denial of service, or allow local users to escalate their privileges.