It was found that systemtap runtime tool (staprun) did not properly enforce the module's path sanity check, when the ad-hoc module instrumentation via user-space probing with user-specified module path was requested. A local user, member of the 'stapusr' group could use this flaw to escalate their privileges.