CVE-2023-1521: GHSL-2023-046: Local Privilege Escalation in sccache - CVE-2023-1521
Impact
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LDPRELOAD.
If the server is run as root (which is the default when installing the snap package), this means a user running the sccache client can get root privileges.
Patches Upgrade to 0.4.0
Workarounds Don't run sccache server as root.
GitHub Security Lab number
GHSL-2023-046
Other sources
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LDPRELOAD.
— GitHub Security Lab
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1521?
CVE-2023-1521 is considered a high severity vulnerability due to its ability to execute arbitrary code with elevated privileges.
How do I fix CVE-2023-1521?
To mitigate CVE-2023-1521, update the 'sccache' client to version 0.4.0 or later.
Who is affected by CVE-2023-1521?
CVE-2023-1521 affects users running the 'sccache' client on Linux when used with a local 'sccache' server.
What units of impact should I expect from CVE-2023-1521?
CVE-2023-1521 can lead to unauthorized access and control of the system, particularly if the server runs as root.
Does CVE-2023-1521 affect versions prior to 0.4.0 of sccache?
Yes, CVE-2023-1521 specifically affects versions of 'sccache' prior to 0.4.0.