A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.
{ "vanir_signatures": [ { "digest": { "length": 777.0, "function_hash": "208378130462840707615846514508483232653" }, "source": "https://github.com/systemd/systemd/commit/06eeacb6fe029804f296b065b3ce91e796e1cd0e", "signature_type": "Function", "target": { "function": "touch_file", "file": "src/basic/fs-util.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-0ea95390" }, { "digest": { "line_hashes": [ "143490046643793043951247385066281749424", "122935519918159594852004239146072093699", "54395448293350274193157192029626465405", "319258269167257065855528611741500025477", "14136216880443083922228792084368357903", "308585633961784689412430179420870598457", "128309604439848126161042702311541266943", "151843754083868116041010403313887337385" ], "threshold": 0.9 }, "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "signature_type": "Line", "target": { "file": "src/test/test-conf-files.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-14049a83" }, { "digest": { "line_hashes": [ "884391527119032421930507393033943967", "71444658684207020711684283464577893821", "129040058516969266729007866096539935790", "171985266963045669393736977086235467711", "167028769458000049328164706596134535271", "325425461498447324481272706372516446726", "73487370959010915169797254673591995470", "166827898435921037420828712229566259421" ], "threshold": 0.9 }, "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "signature_type": "Line", "target": { "file": "src/core/timer.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-4267b89a" }, { "digest": { "length": 765.0, "function_hash": "16651552642822266066331222789744711377" }, "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "signature_type": "Function", "target": { "function": "touch_file", "file": "src/basic/fs-util.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-50486a66" }, { "digest": { "length": 126.0, "function_hash": "202510193103278909526249463735252315663" }, "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "signature_type": "Function", "target": { "function": "touch", "file": "src/basic/fs-util.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-743c9fdd" }, { "digest": { "line_hashes": [ "205574758964764086577373846803576665817", "26172775453165720180949406021269219765", "260867573201901865531530435359545172204", "253223367683081464670724374397409422548" ], "threshold": 0.9 }, "source": "https://github.com/systemd/systemd/commit/06eeacb6fe029804f296b065b3ce91e796e1cd0e", "signature_type": "Line", "target": { "file": "src/basic/fs-util.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-868d732b" }, { "digest": { "line_hashes": [ "97400082154898398970675292924757582953", "110083905208857346320650848691103642371", "307475506367816187332214095585553537513", "135927274798206812626501416543824620549", "3601903755967494894851062893010901710", "220389832517227226628827653175591840104", "13230225266436895651077031958836395872", "150678483076905833111675878602351293786" ], "threshold": 0.9 }, "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "signature_type": "Line", "target": { "file": "src/basic/fs-util.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-a191707d" }, { "digest": { "length": 375.0, "function_hash": "5821552094425570502963670811945135628" }, "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "signature_type": "Function", "target": { "function": "setup_test_dir", "file": "src/test/test-conf-files.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-a8fd9cc9" }, { "digest": { "length": 693.0, "function_hash": "5027209638548168649191285761072337226" }, "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "signature_type": "Function", "target": { "function": "timer_enter_running", "file": "src/core/timer.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-b754c4cb" }, { "digest": { "length": 749.0, "function_hash": "296421973068010747095949689944144467270" }, "source": "https://github.com/systemd/systemd/commit/ee735086f8670be1591fa9593e80dd60163a7a2f", "signature_type": "Function", "target": { "function": "timer_start", "file": "src/core/timer.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-10156-b9e14642" } ] }