REDHAT-BUG-1633243: Medium severity sosreport sos-collector vulnerability

Published Sep 26, 2018
·
Updated

sos-collector does not set any permission when creating new files, thus the default umask is used, making all newly created files readable by all local users. Given the delicacy of the data collected by sos-collector, all files created by the tool, including the sos-reports collected from the cluster machines, should be accessible only the to current user. A local attacker can use this flaw to read sensitive information collected from other machines when a legit user runs sos-collector.

Upstream patch: https://github.com/sosreport/sos-collector/commit/72058f9253e7ed8c7243e2ff76a16d97b03d65ed

Affected Software

1 affected component
sosreport sos-collector

Event History

Sep 26, 2018
Data Sourced
via Red Hat·01:47 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

A local attacker who can access the system where sos-collector is run may read sensitive data collected by another user. The issue concerns files created during collection, including sos-reports retrieved from cluster machines.

2

What conditions are required for exposure?

A legitimate user must run sos-collector, and the process must create files under a default umask that permits other local users to read them. The vulnerability results from sos-collector not explicitly setting restrictive permissions on newly created files.

3

What can be done if patching is delayed?

Use a restrictive umask when running sos-collector and ensure that the directories and files used for collected reports are accessible only to the user performing the collection. Limit local access to systems where sos-collector reports are generated or stored.

4

How can I determine whether collected data may be exposed?

Inspect permissions on files created by sos-collector, including collected sos-reports from cluster machines. Files readable by users other than the collecting user may expose sensitive collected information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203