CVE-2019-3696
NixOS vulnerability analysis and mitigation

Overview

CVE-2019-3696 is a local privilege escalation vulnerability in the Performance Co-Pilot (PCP) software package, specifically in the migrate_tempdirs functionality of the PCP spec file. The vulnerability was discovered in 2019 and affects various versions of Red Hat Enterprise Linux 7 and SUSE Linux Enterprise systems (Red Hat Advisory, SUSE Bug).

Technical details

The vulnerability exists in the migrate_tempdirs function where a malicious local user could exploit the mv command to perform privilege escalation. The issue is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) (NVD CWE). The vulnerability can be exploited by creating specific directory structures and symbolic links in /var/tmp/pmlogger and /var/lib/pcp/tmp/pmlogger directories (SUSE Bug).

Impact

If successfully exploited, this vulnerability allows a local attacker to escalate privileges on the affected system. The attacker could potentially modify critical system files, such as /etc/passwd, leading to complete system compromise (SUSE Bug).

Mitigation and workarounds

Updates have been released to address this vulnerability. SUSE has released security updates SUSE-SU-2020:0355-1, SUSE-SU-2020:0356-1, and SUSE-SU-2020:0357-1 for various affected products. Red Hat has addressed this issue in RHSA-2020:3869 for Red Hat Enterprise Linux 7 (Red Hat Advisory, SUSE Bug).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management