Bug 2404360 - /run/lock/fluidsynth is world-writable
Summary: /run/lock/fluidsynth is world-writable
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: fluidsynth
Version: 41
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Christoph Karl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-16 07:42 UTC by Christophe GRENIER
Modified: 2025-10-30 05:19 UTC (History)
2 users (show)

Fixed In Version: fluidsynth-2.4.8-2.fc41 fluidsynth-2.4.8-2.fc43 fluidsynth-2.4.8-2.fc42 fluidsynth-2.4.8-2.el10_2 fluidsynth-2.4.8-2.el10_1 fluidsynth-2.4.8-2.el9
Clone Of:
Environment:
Last Closed: 2025-10-30 04:19:50 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Christophe GRENIER 2025-10-16 07:42:45 UTC
/usr/lib/tmpfiles.d/fluidsynth.conf contains
d /run/lock/fluidsynth 0777 root root

So everyone can create and deleted files from other "users" in /run/lock/fluidsynth.

As noted in https://lwn.net/Articles/1041316/
"a world-writable directory in /run is a security risk. Any process could write as much as it wanted to /run, which could effectively DoS the system by exhausting space or inodes; filling up /run would then cause critical services, such as udev, to stop working."


Reproducible: Always

Comment 1 Fedora Update System 2025-10-17 17:20:07 UTC
FEDORA-2025-4e7c95f2ef (fluidsynth-2.4.8-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-4e7c95f2ef

Comment 2 Fedora Update System 2025-10-17 17:20:08 UTC
FEDORA-2025-58852b0ec3 (fluidsynth-2.4.8-1.fc41) has been submitted as an update to Fedora 41.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-58852b0ec3

Comment 3 Fedora Update System 2025-10-17 17:20:08 UTC
FEDORA-2025-7bdf853ceb (fluidsynth-2.4.8-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-7bdf853ceb

Comment 4 Fedora Update System 2025-10-18 01:41:33 UTC
FEDORA-2025-4e7c95f2ef has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-4e7c95f2ef`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-4e7c95f2ef

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2025-10-18 02:15:18 UTC
FEDORA-2025-7bdf853ceb has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-7bdf853ceb`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-7bdf853ceb

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2025-10-18 02:35:18 UTC
FEDORA-2025-58852b0ec3 has been pushed to the Fedora 41 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-58852b0ec3`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-58852b0ec3

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Christoph Karl 2025-10-18 06:26:19 UTC
Upstream bug: https://github.com/FluidSynth/fluidsynth/issues/1683

Comment 8 Fedora Update System 2025-10-21 17:44:30 UTC
FEDORA-2025-0ea3179bb0 (fluidsynth-2.4.8-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-0ea3179bb0

Comment 9 Fedora Update System 2025-10-21 17:44:31 UTC
FEDORA-2025-1131df0f70 (fluidsynth-2.4.8-2.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-1131df0f70

Comment 10 Fedora Update System 2025-10-21 17:44:32 UTC
FEDORA-EPEL-2025-5aefff4853 (fluidsynth-2.4.8-2.el10_1) has been submitted as an update to Fedora EPEL 10.1.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5aefff4853

Comment 11 Fedora Update System 2025-10-22 01:08:21 UTC
FEDORA-2025-1131df0f70 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-1131df0f70`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-1131df0f70

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 12 Fedora Update System 2025-10-22 01:40:53 UTC
FEDORA-EPEL-2025-1fe5205aa6 has been pushed to the Fedora EPEL 10.2 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-1fe5205aa6

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 13 Fedora Update System 2025-10-22 01:49:46 UTC
FEDORA-EPEL-2025-ae4b2d1417 has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-ae4b2d1417

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 14 Fedora Update System 2025-10-22 01:58:45 UTC
FEDORA-EPEL-2025-5aefff4853 has been pushed to the Fedora EPEL 10.1 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5aefff4853

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 15 Fedora Update System 2025-10-22 02:27:40 UTC
FEDORA-2025-0ea3179bb0 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-0ea3179bb0`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-0ea3179bb0

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 16 Fedora Update System 2025-10-22 02:52:43 UTC
FEDORA-2025-6db4dcdf66 has been pushed to the Fedora 41 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-6db4dcdf66`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-6db4dcdf66

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 17 Fedora Update System 2025-10-30 04:19:50 UTC
FEDORA-2025-6db4dcdf66 (fluidsynth-2.4.8-2.fc41) has been pushed to the Fedora 41 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 18 Fedora Update System 2025-10-30 04:30:41 UTC
FEDORA-2025-0ea3179bb0 (fluidsynth-2.4.8-2.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 19 Fedora Update System 2025-10-30 04:34:43 UTC
FEDORA-2025-1131df0f70 (fluidsynth-2.4.8-2.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 20 Fedora Update System 2025-10-30 04:39:04 UTC
FEDORA-EPEL-2025-1fe5205aa6 (fluidsynth-2.4.8-2.el10_2) has been pushed to the Fedora EPEL 10.2 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 21 Fedora Update System 2025-10-30 05:05:17 UTC
FEDORA-EPEL-2025-5aefff4853 (fluidsynth-2.4.8-2.el10_1) has been pushed to the Fedora EPEL 10.1 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 22 Fedora Update System 2025-10-30 05:19:57 UTC
FEDORA-EPEL-2025-ae4b2d1417 (fluidsynth-2.4.8-2.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.