Vulnerabilities in PCP and Nix that allow privilege escalation in the system

In the PCP (Performance Co-Pilot) toolkit, used for collecting system performance statistics (for example, it is utilized in the Cockpit interface), two vulnerabilities have been identified. The first vulnerability (CVE-2024-45770) is present in the pmpost utility, which is designed to send messages to the log and can be launched with elevated privileges under certain conditions. Exploiting this vulnerability allows for code execution with root privileges, but to carry out the attack, access to the PCP account is necessary. The attack involves replacing the symbolic link for the file "/var/log/pcp/NOTICES", into which a process runs with root privileges without using the O_NOFOLLOW flag when opening the file.

The second vulnerability in PCP (CVE-2024-45769) affects the background process pcmd and leads to an out-of-bounds memory access when sending specially crafted data. The risk of this vulnerability is mitigated by the fact that by default pcmd does not accept network requests from other systems. The vulnerabilities have been fixed in the PCP 6.3.1 release. The issues were identified during an audit conducted by developers from the SUSE project.

Additionally, a vulnerability (CVE-2024-45593) has been identified in the Nix package manager, used in the NixOS distribution. This vulnerability allows for writing to arbitrary areas of the file system during the unpacking of specially crafted files in the NAR (Nix Archive) format, limited by the permissions of the handler being executed (the unpacking process is run as root when using the Nix background process). This issue is present in the Nix 2.24 branch and has been addressed in the 2.24.6 release.

Additionally, a publication warning has been issued regarding the detection of a critical vulnerability affecting GNU/Linux distributions that allows for remote code execution without authentication in the system. Currently, no information is provided about the essence of the problem or the subsystems it affects, only that an initial report on the issue is planned to be published on September 30, and a complete report with details on October 6, in coordination with distribution developers. No CVE has been assigned to the issue yet. According to the researcher who identified the problem, Canonical and Red Hat have rated the vulnerability as critical (9.9 out of 10).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster