CVE-2016-10156

NameCVE-2016-10156
DescriptionA flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: local)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
systemd (PTS)jessie215-17+deb8u7fixed
jessie (security)215-17+deb8u13fixed
stretch232-25+deb9u12fixed
stretch (security)232-25+deb9u11fixed
buster241-7~deb10u1fixed
bullseye, sid242-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
systemdsource(unstable)229-1high
systemdsourcejessie(not affected)
systemdsourcewheezy(not affected)

Notes

[jessie] - systemd <not-affected> (Vulnerability introduced in v228)
[wheezy] - systemd <not-affected> (Vulnerability introduced in v228)
https://bugzilla.suse.com/show_bug.cgi?id=1020601
Fixed by: https://github.com/systemd/systemd/commit/06eeacb6fe029804f296b065b3ce91e796e1cd0e (v229)
Introduced by: https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f (v228)

Search for package or bug name: Reporting problems