CVE-2022-31250: keylime %post scriplet allows for privilege escalation from keylime user to root
Published Jul 20, 2022
·Updated
A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.
Affected Software
1 affected component
openSUSE Tumbleweed<6.4.2-1.1
Event History
Jul 20, 2022
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-31250.
2
What is the severity of CVE-2022-31250?
The severity of CVE-2022-31250 is high (7.8).
3
Which software is affected by CVE-2022-31250?
CVE-2022-31250 affects openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.
4
How can the vulnerability CVE-2022-31250 be exploited?
CVE-2022-31250 can be exploited by local attackers to escalate from the keylime user to root using a UNIX Symbolic Link (Symlink) Following vulnerability.
5
Is there a fix available for CVE-2022-31250?
Yes, upgrading to keylime version 6.4.2-1.1 or later will fix the vulnerability CVE-2022-31250.