A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.
{ "vanir_signatures": [ { "id": "CVE-2016-10156-14049a83", "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "deprecated": false, "signature_type": "Line", "target": { "file": "src/test/test-conf-files.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "143490046643793043951247385066281749424", "122935519918159594852004239146072093699", "54395448293350274193157192029626465405", "319258269167257065855528611741500025477", "14136216880443083922228792084368357903", "308585633961784689412430179420870598457", "128309604439848126161042702311541266943", "151843754083868116041010403313887337385" ], "threshold": 0.9 } }, { "id": "CVE-2016-10156-4267b89a", "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "deprecated": false, "signature_type": "Line", "target": { "file": "src/core/timer.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "884391527119032421930507393033943967", "71444658684207020711684283464577893821", "129040058516969266729007866096539935790", "171985266963045669393736977086235467711", "167028769458000049328164706596134535271", "325425461498447324481272706372516446726", "73487370959010915169797254673591995470", "166827898435921037420828712229566259421" ], "threshold": 0.9 } }, { "id": "CVE-2016-10156-50486a66", "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "deprecated": false, "signature_type": "Function", "target": { "file": "src/basic/fs-util.c", "function": "touch_file" }, "signature_version": "v1", "digest": { "function_hash": "16651552642822266066331222789744711377", "length": 765.0 } }, { "id": "CVE-2016-10156-743c9fdd", "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "deprecated": false, "signature_type": "Function", "target": { "file": "src/basic/fs-util.c", "function": "touch" }, "signature_version": "v1", "digest": { "function_hash": "202510193103278909526249463735252315663", "length": 126.0 } }, { "id": "CVE-2016-10156-a191707d", "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "deprecated": false, "signature_type": "Line", "target": { "file": "src/basic/fs-util.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "97400082154898398970675292924757582953", "110083905208857346320650848691103642371", "307475506367816187332214095585553537513", "135927274798206812626501416543824620549", "3601903755967494894851062893010901710", "220389832517227226628827653175591840104", "13230225266436895651077031958836395872", "150678483076905833111675878602351293786" ], "threshold": 0.9 } }, { "id": "CVE-2016-10156-a8fd9cc9", "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "deprecated": false, "signature_type": "Function", "target": { "file": "src/test/test-conf-files.c", "function": "setup_test_dir" }, "signature_version": "v1", "digest": { "function_hash": "5821552094425570502963670811945135628", "length": 375.0 } }, { "id": "CVE-2016-10156-b754c4cb", "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "deprecated": false, "signature_type": "Function", "target": { "file": "src/core/timer.c", "function": "timer_enter_running" }, "signature_version": "v1", "digest": { "function_hash": "5027209638548168649191285761072337226", "length": 693.0 } }, { "id": "CVE-2016-10156-b9e14642", "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "deprecated": false, "signature_type": "Function", "target": { "file": "src/core/timer.c", "function": "timer_start" }, "signature_version": "v1", "digest": { "function_hash": "296421973068010747095949689944144467270", "length": 749.0 } } ] }