suse · CVE-2016-10156

Quick triage

Priority: high 公開: 2021-05-30 13:49:10 UTC Updated: 2026-04-18 15:51:34 UTC

参照: Official suse advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-10156 severity important: SUSE including 536 source package names (0.9.1:libsystemd0-228-132.1, 0.9.1:libudev1-228-132.1, …), 652 product×package rows across 58 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (58 product lines)): Fixed 472, Known Affected 157, Known Not Affected 23.

Description:

A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.

cvelogic Threat Intelligence