Red Hat Bugzilla – Bug 1545017
CVE-2018-6954 systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files
Last modified: 2018-07-03 04:05:27 EDT
systemd-tmpfiles in systemd through version 237 mishandles symlinks present in non-terminal path components, allowing local users to obtain ownership of arbitrary files under certain configurations. Depending on the configuration and access to files in /etc/tmpfiles.d, a local user can potentially create a symlink allowing them obtain full access to arbitrary files when the systemd-tmpfiles command is run. This occurs even if the fs.protected_symlinks sysctl is turned on. Upstream Issue: https://github.com/systemd/systemd/issues/7986
Created systemd tracking bugs for this issue: Affects: fedora-all [bug 1545018]
Patches: https://github.com/systemd/systemd/pull/8358 https://github.com/systemd/systemd/pull/8822