A vulnerability in systemd-coredump allows the contents of suid program memory to be determined.
A vulnerability (CVE-2022-4415) has been identified in the systemd-coredump component, which handles core dumps generated after process crashes, allowing a non-privileged local user to determine the memory contents of privileged processes running with the suid root flag. The presence of the issue in the default configuration has been confirmed in openSUSE, Arch, Debian, Fedora, and SLES distributions. The vulnerability is caused by a lack of proper handling of the sysctl parameter fs.suid_dumpable in systemd-coredump, which, when set to […]
