CVE-2022-31252
Linux openSUSE vulnerability analysis and mitigation

Overview

The vulnerability CVE-2022-31252 affects the permissions package in SUSE Linux Enterprise Server and openSUSE Leap systems. The issue specifically involves the chkstat component not properly checking for group-writable parent directories or target files in the safeOpen() function. This vulnerability was discovered in September 2022 and affects multiple versions of the permissions package, including SUSE Linux Enterprise Server 12-SP5 and openSUSE Leap 15.3 (SUSE Bugzilla).

Technical details

The vulnerability is classified under CWE-863 (Incorrect Authorization) and involves a security flaw in the chkstat's safeopen() implementation. The core issue lies in the missing group-write checks in the algorithm, which could potentially allow unauthorized modifications to sensitive files. The vulnerability received a CVSS v3.1 score of 6.7, indicating moderate severity ([SUSE Bugzilla](https://bugzilla.suse.com/showbug.cgi?id=1203018)).

Impact

The primary impact of this vulnerability is that setuid-root bits or capabilities could potentially be assigned to untrusted binaries. While such configurations are rare in SUSE distributions, it represents a formal security vulnerability that could lead to privilege escalation (SUSE Bugzilla).

Mitigation and workarounds

The issue has been addressed through security updates across multiple SUSE products. Fixed versions were released for SUSE Linux Enterprise Server 12-SP5 (permissions-20170707-6.10.1), openSUSE Leap 15.3, and other affected systems. Users are advised to update their systems to the patched versions (SUSE Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux openSUSE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13470HIGH7.7
  • Linux DebianLinux Debian
  • rnp
NoYesNov 21, 2025
CVE-2025-61915MEDIUM6
  • OpenPrinting CUPSOpenPrinting CUPS
  • libcups2-32bit
NoYesNov 29, 2025
CVE-2025-58436MEDIUM5.1
  • OpenPrinting CUPSOpenPrinting CUPS
  • cups-devel
NoYesNov 29, 2025
CVE-2025-9820N/AN/A
  • GnuTLSGnuTLS
  • gnutls28
NoYesNov 21, 2025
CVE-2025-13402N/AN/A
  • Linux FedoraLinux Fedora
  • librnp
NoYesNov 21, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management