REDHAT-BUG-803358: Race Condition
A TOCTOU race condition was found in the way the systemd-logind login manager of the systemd, a system and service manager for Linux, performed removal of particular records related with user session upon user logout. A local attacker could use this flaw to conduct symbolic link attacks, potentially leading to removal of arbitrary system file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-803358?
The severity of REDHAT-BUG-803358 is classified as moderate due to the potential for local attackers to exploit the race condition.
How do I fix REDHAT-BUG-803358?
To fix REDHAT-BUG-803358, update your systemd and systemd-logind packages to the latest available versions from the vendor.
What type of attack is associated with REDHAT-BUG-803358?
REDHAT-BUG-803358 is associated with symbolic link attacks that exploit a time-of-check to time-of-use (TOCTOU) race condition.
Who is affected by REDHAT-BUG-803358?
REDHAT-BUG-803358 affects users of systemd-logind in Linux systems that use systemd for managing services and sessions.
Can a remote attacker exploit REDHAT-BUG-803358?
No, REDHAT-BUG-803358 can only be exploited by a local attacker with access to the system.