Util-linux File Locking Race Condition Vulnerability

BID:5344

Info

Util-linux File Locking Race Condition Vulnerability

Bugtraq ID: 5344
Class: Race Condition Error
CVE:
Remote: No
Local: Yes
Published: Jul 29 2002 12:00AM
Updated: Jul 29 2002 12:00AM
Credit: Discovered by Michal Zalewski <[email protected]>.
Vulnerable: Redhat util-linux-2.11n-12.i386.rpm
+ Redhat Linux 7.3
Redhat util-linux-2.10s-12.i386.rpm
+ Redhat Linux 7.1
Redhat util-linux-2.10m-12.i386.rpm
+ Redhat Linux 7.0
Redhat util-linux-2.10f-7.i386.rpm
+ Redhat Linux 6.2
Redhat mount-2.11n-12.i386.rpm
+ Redhat Linux 7.3
Redhat losetup-2.11n-12.i386.rpm
+ Redhat Linux 7.3
Redhat Linux 7.3
Redhat Linux 7.2 ia64
Redhat Linux 7.2 alpha
Redhat Linux 7.2
Redhat Linux 7.1 ia64
Redhat Linux 7.1 alpha
Redhat Linux 7.1
Redhat Linux 7.0 alpha
Redhat Linux 7.0
Redhat Linux 6.2 sparc
Redhat Linux 6.2 alpha
Redhat Linux 6.1 sparc
Redhat Linux 6.1 alpha
Redhat Linux 6.1
Redhat Linux 6.0 sparc
Redhat Linux 6.0 alpha
Redhat Linux 6.0
Redhat Linux 6.2
Mandriva Linux Mandrake 8.2 ppc
Mandriva Linux Mandrake 8.2
Mandriva Linux Mandrake 8.1 ia64
Mandriva Linux Mandrake 8.1
Mandriva Linux Mandrake 8.0 ppc
Mandriva Linux Mandrake 8.0
Mandriva Linux Mandrake 7.2
Mandriva Linux Mandrake 7.1
Mandriva Linux Mandrake 7.0
MandrakeSoft Single Network Firewall 7.2
MandrakeSoft Corporate Server 1.0.1
HP Secure OS software for Linux 1.0
Caldera OpenLinux Workstation 3.1.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Server 3.1
Not Vulnerable:

Discussion

Util-linux File Locking Race Condition Vulnerability

The util-linux package is a set of commonly used system utilities such as 'chfn' and 'chsh'. It is included with many Linux distributions.

A race condition has been reported in code shared by the util-linux utilities. The condition is related to file locking. Failure to check for the existence of a lockfile prior to sensitive operations may, under specific circumstances, open a window of opportunity for attack. The util-linux utilities often write to sensitive files such as /etc/passwd/. Attackers may exploit the condition to inject arbitrary data into these files to elevate privileges.

The reported attacks are complex, time dependent and require specific circumstances such as system administrator interaction and a large passwd file.

Red Hat Linux is known to ship with util-linux as a core component. Other distributions, those that are derived from Red Hat in particular, may also be vulnerable.

It should be noted that the utilities included with the shadow-utils package (shipped with SuSE Linux) are not vulnerable.

Exploit / POC

Util-linux File Locking Race Condition Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Util-linux File Locking Race Condition Vulnerability

Solution:
An unofficial source code patch is available. Red Hat has released fixes in bulletin RHSA-2002:132-14 (see references section).

Users of HP Secure OS Software for Linux Release 1.0 are advised to install the available Red Hat fixes.

SCO has released a security advisory. Fixes are available.

Fixes:


Redhat util-linux-2.10s-12.i386.rpm

Redhat Linux 6.2

Redhat util-linux-2.11n-12.i386.rpm

Redhat util-linux-2.10m-12.i386.rpm

Redhat mount-2.11n-12.i386.rpm

Redhat util-linux-2.10f-7.i386.rpm

Redhat losetup-2.11n-12.i386.rpm

MandrakeSoft Corporate Server 1.0.1

Caldera OpenLinux Server 3.1

Caldera OpenLinux Workstation 3.1

Caldera OpenLinux Server 3.1.1

Caldera OpenLinux Workstation 3.1.1

Redhat Linux 6.2 alpha

Redhat Linux 6.2 sparc

Redhat Linux 7.0

Redhat Linux 7.0 alpha

Mandriva Linux Mandrake 7.1

Redhat Linux 7.1 alpha

Redhat Linux 7.1 ia64

Redhat Linux 7.1

Mandriva Linux Mandrake 7.2

Redhat Linux 7.2 ia64

Redhat Linux 7.2

MandrakeSoft Single Network Firewall 7.2

Redhat Linux 7.2 alpha

Redhat Linux 7.3

Mandriva Linux Mandrake 8.0 ppc

Mandriva Linux Mandrake 8.0

Mandriva Linux Mandrake 8.1 ia64

Mandriva Linux Mandrake 8.1

Mandriva Linux Mandrake 8.2

Mandriva Linux Mandrake 8.2 ppc

References

Util-linux File Locking Race Condition Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report