CVE-2022-0987: Infoleak
A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.
Other sources
A vulnerability was found in PackageKit in the way some of the methods exposed by the Transaction interface examine files without dropping privileges. The InstallFiles method, for example, will fail silently with a non-existing file, however if the file exists it will read the contents of the file and take longer to return than a non-existing file will. This vulnerability allows a local user to know whether a file owned by root or other users exists.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0987 about?
CVE-2022-0987 is about a flaw in PackageKit that allows a local user to determine the existence of files owned by root or other users.
How severe is CVE-2022-0987?
CVE-2022-0987 has a severity rate of 3.3, which is considered low.
What software is affected by CVE-2022-0987?
CVE-2022-0987 affects PackageKit and Redhat Enterprise Linux version 9.0.