Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.
{ "urgency": "not yet assigned" }