CVE-2023-3899
Rocky Linux vulnerability analysis and mitigation

Overview

CVE-2023-3899 affects the subscription-manager package, discovered and disclosed in July 2023. The vulnerability exists in the D-Bus interface com.redhat.RHSM1 which exposes methods that could change the registration state. This security issue affects Red Hat Enterprise Linux systems and related products running subscription-manager versions from 1.26.15-1 and above (Red Hat CVE).

Technical details

The vulnerability stems from inadequate authorization in the D-Bus interface com.redhat.RHSM1, specifically in the Config.SetAll() method. The interface exposes numerous methods to all users that can modify the registration state. The CVSS base score is 7.8 HIGH with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating local access requirements but high impact potential (NVD).

Impact

The vulnerability allows a low-privileged local user to tamper with the system's registration state, including the ability to unregister the system or modify current entitlements. More critically, through the Config.SetAll() method, attackers can set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be exploited to achieve local privilege escalation to unconfined root (Red Hat Bugzilla).

Mitigation and workarounds

Red Hat has released security updates to address this vulnerability across multiple product versions. Updates are available through RHSA-2023:4701 through RHSA-2023:4708 advisories for various versions of Red Hat Enterprise Linux. Fedora has also released fixes in subscription-manager version 1.29.37 for Fedora 37 and 38 (Fedora Update).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management