Back

HIGH

coreutils: race condition vulnerability in chown and chgrp

Published Jan 4, 2018

Description

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

Affected products

Remediation

Red Hat statement

For this vulnerability the fix was an update to the documentation. For more details please visit: https://www.openwall.com/lists/oss-security/2018/01/04/3 http://michael.orlitzky.com/cves/cve-2017-18018.xhtml Red Hat Enterprise Linux 8 ships already updated version of the coreutils package (version 8.30).

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 4, 2018
Updated Jun 9, 2025
Reserved Jan 3, 2018
CISA Vulnrichment
Updated Jun 9, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 20, 2017
ENISA EUVD
Assigner mitre
Published Jan 4, 2018
Updated Jun 9, 2025
Exploited since n/a
EUVD-2017-9158