https://seclists.org/oss-sec/2024/q1/168: Performance Co-Pilot (pcp): Unsafe use of Directories in /var/lib/pcp and /var/log/pcp breaks pcp Service User Isolation (CVE-2023-6917)
Published Feb 28, 2024
·Updated
Affected Software
1 affected component
Performance Co-Pilot PCP
Frequently Asked Questions
1
What is the severity of CVE-2023-6917?
CVE-2023-6917 is considered a high severity vulnerability due to its potential to allow local privilege escalation from the pcp service user to root.
2
How do I fix CVE-2023-6917?
To mitigate CVE-2023-6917, you should update to the latest version of Performance Co-Pilot that addresses this vulnerability.
3
What does CVE-2023-6917 exploit?
CVE-2023-6917 exploits unsafe use of directories in /var/lib/pcp and /var/log/pcp, compromising user isolation.
4
Who is affected by CVE-2023-6917?
All users of Performance Co-Pilot who have access to the affected directories are at risk of CVE-2023-6917.
5
What is Performance Co-Pilot as it relates to CVE-2023-6917?
Performance Co-Pilot is a performance analysis toolkit that becomes vulnerable to local privilege escalation through CVE-2023-6917.