Threat Advisory

Linux suTrap LPE Flaw Grants Root Access via Hijacked Sessions

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities with affected versions The vulnerability currently impacts multiple popular enterprise Linux distributions have been identified in Linux suTrap and shadow-utils packages, which allow an unprivileged user to gain root access during an active session. The vulnerability details and a proof-of-concept exploit code are now publicly disclosed.

CVE-2023-4641 (CVSS 9.8 — Critical): This vulnerability stems from how the shadow-utils package handles interactive terminal sessions, allowing attackers to inject keystrokes into the shared terminal buffer using a background process and abusing the legacy TIOCSTI ioctl feature.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities with affected versions The vulnerability currently impacts multiple popular enterprise Linux distributions have been identified in Linux suTrap and shadow-utils packages, which allow an unprivileged user to gain root access during an active session. The vulnerability details and a proof-of-concept exploit code are now publicly disclosed.

CVE-2023-4641 (CVSS 9.8 — Critical): This vulnerability stems from how the shadow-utils package handles interactive terminal sessions, allowing attackers to inject keystrokes into the shared terminal buffer using a background process and abusing the legacy TIOCSTI ioctl feature.[emaillocker id="1283"]

CVE-2024-56433 (CVSS 9.8 — Critical): The vulnerability details are not explicitly stated in this article. These vulnerabilities collectively present a severe security risk, particularly for system administrators who frequently use the su command to drop privileges for application testing. Administrators should immediately update their shadow-utils package and avoid running interactive su sessions from root to unprivileged accounts. These vulnerabilities collectively present a severe security risk, particularly for system administrators who frequently use the su command to drop privileges for application testing.

These vulnerabilities collectively present a severe security risk, particularly for system administrators who frequently use the su command to drop privileges for application testing.

RECOMMENDATION:

We recommend you to update shadow-utils to version 4.20.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu