Back

CRITICAL

nfs-utils: root-owned files stored in insecure /var/lib/nfs directory

Published Sep 19, 2019

Description

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of nfs-utils as shipped with Red Hat Enterprise Linux 6, 7, and 8 as /var/lib/nfs directory is owned by root:root.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner suse
Published Sep 19, 2019
Updated Sep 17, 2024
Reserved Jan 3, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 17, 2019