pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to become the owner of root-owned files.
During package installation, the post-installation script pkg_postinst calls the chown command in a manner that is unnecessary, operating on files in the active root filesystem. A user acting in the context of the slurm account can exploit this to take ownership of files owned by the root user. The error is classified as CWE-732, which is incorrect permission assignment to critical resources.
An attacker with access to the slurm account can become the owner of system files belonging to root, which in practice can lead to privilege escalation and complete takeover of the system.
Apply patches available from the vendor according to the references (https://bugs.gentoo.org/631552). It is recommended to update the Gentoo ebuild package for Slurm to a version free from the described vulnerability.
Gentoo ebuild for Slurm in versions through 22.05.3 inclusive.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGentoo Ebuild For Slurm
APPGentoo≤ 22.05.3
Related vulnerabilities
Heap-based buffer overflow w rsync daemon — zapis poza granicami bufora sum2
Brak weryfikacji podpisu PGP w Gentoo Portage emerge-webrsync
SQL Injection z możliwością RCE w Gentoo Soko (packages.gentoo.org)
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an att...
Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injecti...