
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2023-6917) has been identified in the Performance Co-Pilot (PCP) package, discovered by Matthias Gerstner from the SUSE Linux security team. The vulnerability stems from mixed privilege levels in systemd services associated with PCP, where some services operate with limited PCP user/group privileges while others have full root privileges. This vulnerability was disclosed on February 28, 2024, and affects PCP implementations in various Linux distributions (Red Hat CVE, NVD).
The vulnerability arises from the interaction between privileged root processes and directories owned by unprivileged PCP users. Specifically, shared directory structures such as '/var/lib/pcp/tmp' and '/var/log/pcp' (both owned by pcp:pcp with mode 775) are accessed by services running with different privilege levels. The CVSS v3.1 base score is 6.0 (Moderate), with the vector string CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N (Red Hat CVE).
The vulnerability can lead to the compromise of PCP user isolation and facilitate local PCP-to-root privilege escalation exploits. The severity is classified as moderate rather than important due to mitigating factors, including the requirement of an already compromised pcp system account and specific conditions such as the existence of symbolic links and the ability to manipulate directory structures (Red Hat CVE).
Exploitation requires local access and an already compromised pcp system account. The vulnerability can be exploited through symlink attacks when privileged root processes interact with directories or directory trees controlled by unprivileged users (Red Hat Bugzilla).
Red Hat has addressed this vulnerability in Red Hat Enterprise Linux 9 through the security advisory RHSA-2024:2213, which provides an update to PCP version 6.2.0-1. Currently, no specific workarounds are available that meet Red Hat Product Security criteria for ease of use and deployment (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."