CVE-2023-26604
published 2023-03-03CVE-2023-26604: systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.05%
60.5th percentile
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apport_project | apport | >= 0 < 2.20.9-0ubuntu7.29 | 2.20.9-0ubuntu7.29 |
| apport_project | apport | >= 0 < 2.20.11-0ubuntu27.26 | 2.20.11-0ubuntu27.26 |
| apport_project | apport | >= 0 < 2.20.11-0ubuntu82.4 | 2.20.11-0ubuntu82.4 |
| canonical | apport | <= 2.26.0 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | apport | <= 2.26.0 | — |
| debian | debian_linux | — | — |
| debian | systemd | < systemd 247.1-2 (bookworm) | systemd 247.1-2 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-44_on_cbl_mariner_1.0 | — | — |
| systemd_project | systemd | < 246.7 | 246.7 |
| systemd_project | systemd | >= 0 < 247.1-2 | 247.1-2 |
| systemd_project | systemd | >= 0 < 247.1-2 | 247.1-2 |
| systemd_project | systemd | >= 0 < 247.1-2 | 247.1-2 |
| systemd_project | systemd | >= 0 < 247.1-2 | 247.1-2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qgrc-7333-5cgx: A privilege escalation attack was found in apport-cli 2
ghsa_unreviewed·2023-04-14·CVSS 7.8
CVE-2023-1326 [HIGH] CWE-269 GHSA-qgrc-7333-5cgx: A privilege escalation attack was found in apport-cli 2
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit.
OSV
CVE-2023-1326: A privilege escalation attack was found in apport-cli 2
osv·2023-04-13·CVSS 7.8
CVE-2023-1326 [HIGH] CVE-2023-1326: A privilege escalation attack was found in apport-cli 2
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit.
OSV
CVE-2023-26604: systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e
osv·2023-03-03·CVSS 7.8
CVE-2023-26604 [HIGH] CVE-2023-26604: systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
GHSA
GHSA-8989-8fhv-vq42: systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e
ghsa_unreviewed·2023-03-03
CVE-2023-26604 [HIGH] CWE-269 GHSA-8989-8fhv-vq42: systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Oracle
Oracle Oracle Communications Risk Matrix: Oracle Linux (systemd) — CVE-2023-26604
vendor_oracle·2023-10-15·CVSS 7.8
CVE-2023-26604 [HIGH] Oracle Oracle Communications Risk Matrix: Oracle Linux (systemd) — CVE-2023-26604
Oracle Oracle Communications Risk Matrix: Oracle Linux (systemd) vulnerability
CVE: CVE-2023-26604
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2023 (OCT 2023)
Microsoft
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations e.g. plausible sudoers files in which the "systemctl status" command may be executed. Specifically
vendor_msrc·2023-03-14·CVSS 7.8
CVE-2023-26604 [HIGH] systemd before 247 does not adequately block local privilege escalation for some Sudo configurations e.g. plausible sudoers files in which the "systemctl status" command may be executed. Specifically
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations e.g. plausible sudoers files in which the "systemctl status" command may be executed. Specifically systemd does not set LESSSECURE to 1 and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo because less executes as root when the terminal size is too small to show the complete systemctl output.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of
Red Hat
systemd: privilege escalation via the less pager
vendor_redhat·2023-03-03·CVSS 7.8
CVE-2023-26604 [HIGH] systemd: privilege escalation via the less pager
systemd: privilege escalation via the less pager
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
A vulnerability was found in the systemd package. The systemd package does not adequately block local privilege escalation for some sudo configurations, for example, plausible sudoers files, in which the "systemctl status" command may be executed. Specifically, sy
Debian
CVE-2023-26604: systemd - systemd before 247 does not adequately block local privilege escalation for some...
vendor_debian·2023·CVSS 7.8
CVE-2023-26604 [HIGH] CVE-2023-26604: systemd - systemd before 247 does not adequately block local privilege escalation for some...
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Scope: local
bookworm: resolved (fixed in 247.1-2)
bullseye: resolved (fixed in 247.1-2)
forky: resolved (fixed in 247.1-2)
sid: resolved (fixed in 247.1-2)
trixie: resolved (fixed in 247.1-2)
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.htmlhttps://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340https://lists.debian.org/debian-lts-announce/2023/03/msg00032.htmlhttps://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7https://security.netapp.com/advisory/ntap-20230505-0009/http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.htmlhttps://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340https://lists.debian.org/debian-lts-announce/2023/03/msg00032.htmlhttps://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7https://security.netapp.com/advisory/ntap-20230505-0009/
2023-03-03
Published