Bug 2024174 (CVE-2021-3982)

Summary: CVE-2021-3982 gnome-shell: Distributions using CAP_SYS_NICE in gnome-shell may be exposed to privilege escalation
Product: [Other] Security Response Reporter: Marco Benatto <mbenatto>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: adscvr, ajak, fmuellner, gnome-sig, jadahl, otaylor, philip.wyett, rstrode, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-11-30 15:24:07 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2026996, 2026997    
Bug Blocks: 1943154, 2025016    

Description Marco Benatto 2021-11-17 13:49:19 UTC
Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other services running in the same machine.

Comment 2 Marco Benatto 2021-11-26 19:44:15 UTC
Created gnome-shell tracking bugs for this issue:

Affects: fedora-all [bug 2026996]

Comment 4 Marco Benatto 2021-11-30 15:24:07 UTC
Closing this bug as NOTABUG as any RHEL version is really affected by this.

Comment 5 John Helmert III 2022-04-30 21:56:16 UTC
Why did it take 5 months for this CVE to be made public?

The only upstream reference in the CVE for this issue was closed as a duplicate. Please add these as references:

https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/2284
https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/2060