A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
{ "vanir_signatures": [ { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "254079786612781049752644905636957680265", "294274046992081162952296487750956254301", "155366078330810701501756008017410041559", "78695319910546846342802579537748469684", "210996109935367098375678887685511520728", "98137586820320364725232538173660781994", "65933351546802506335929140347031909077", "83420384204751459509845015373717758237", "8908594386565829095929436899090658237", "284598799330760466641087629932413299336", "118406465720091467550330037024887373950", "27401481682754817741697086533904416236", "231859714326979121881491685551060707006", "20655087195420992266114436202151015057" ] }, "source": "https://github.com/util-linux/util-linux/commit/dffab154d29a288aa171ff50263ecc8f2e14a891", "deprecated": false, "target": { "file": "login-utils/su-common.c" }, "signature_type": "Line", "id": "CVE-2017-2616-2c18f385" }, { "signature_version": "v1", "digest": { "length": 2743.0, "function_hash": "315096434462509264335874598434674430021" }, "source": "https://github.com/util-linux/util-linux/commit/dffab154d29a288aa171ff50263ecc8f2e14a891", "deprecated": false, "target": { "file": "login-utils/su-common.c", "function": "create_watching_parent" }, "signature_type": "Function", "id": "CVE-2017-2616-f61c0019" } ] }