A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
{ "vanir_signatures": [ { "id": "CVE-2017-2616-2c18f385", "digest": { "line_hashes": [ "254079786612781049752644905636957680265", "294274046992081162952296487750956254301", "155366078330810701501756008017410041559", "78695319910546846342802579537748469684", "210996109935367098375678887685511520728", "98137586820320364725232538173660781994", "65933351546802506335929140347031909077", "83420384204751459509845015373717758237", "8908594386565829095929436899090658237", "284598799330760466641087629932413299336", "118406465720091467550330037024887373950", "27401481682754817741697086533904416236", "231859714326979121881491685551060707006", "20655087195420992266114436202151015057" ], "threshold": 0.9 }, "source": "https://github.com/util-linux/util-linux/commit/dffab154d29a288aa171ff50263ecc8f2e14a891", "signature_version": "v1", "target": { "file": "login-utils/su-common.c" }, "deprecated": false, "signature_type": "Line" }, { "id": "CVE-2017-2616-f61c0019", "digest": { "length": 2743.0, "function_hash": "315096434462509264335874598434674430021" }, "source": "https://github.com/util-linux/util-linux/commit/dffab154d29a288aa171ff50263ecc8f2e14a891", "signature_version": "v1", "target": { "function": "create_watching_parent", "file": "login-utils/su-common.c" }, "deprecated": false, "signature_type": "Function" } ] }