Back

HIGH

pesign: Local privilege escalation on pesign systemd service

Published Feb 2, 2023

Description

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 2, 2023
Updated Mar 26, 2025
Reserved Oct 17, 2022
CISA Vulnrichment
Updated Mar 26, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 31, 2023
ENISA EUVD
Assigner redhat
Published Feb 2, 2023
Updated Mar 26, 2025
Exploited since n/a
EUVD-2022-42926