Back

LOW

kernel: audit not logging access to syscall open_by_handle_at for users with CAP_DAC_READ_SEARCH capability

Published Mar 30, 2022

Description

A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem

Affected products

Remediation

Red Hat mitigation

This syscall can still be audited by using the 'syscall auditing feature' by passing open_by_handle_at to it in the rule. Existing auditing ruleset requirements generally use this mechanism.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 30, 2022
Updated Aug 4, 2024
Reserved Dec 17, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 5, 2021