CVE-2023-1326: local privilege escalation in apport-cli
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-1326?
CVE-2023-1326 is a privilege escalation attack found in apport-cli 2.26.0 and earlier.
What is the severity of CVE-2023-1326?
CVE-2023-1326 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2023-1326?
The affected software versions include apport-cli 2.26.0 and earlier, as well as Canonical Apport, and various versions of Canonical Ubuntu Linux (18.04, 20.04, 22.04, and 22.10).
How can I fix CVE-2023-1326?
To fix CVE-2023-1326, you should update to the latest version of apport (2.26.1 for Ubuntu) or apply the recommended security patches provided by Canonical Ubuntu Linux.
Where can I find more information about CVE-2023-1326?
You can find more information about CVE-2023-1326 on the Debian security tracker, GitHub repository of Canonical Apport, and the Ubuntu security notices.