A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
References
Link | Resource |
---|---|
https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4 | Patch Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637 | Exploit Issue Tracking Third Party Advisory |
http://seclists.org/oss-sec/2016/q4/352 | Exploit Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/94128 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-08-01 06:29
Updated : 2023-02-12 15:26
NVD link : CVE-2016-8637
Mitre link : CVE-2016-8637
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
dracut_project
- dracut