• CVE-2024-22017

发布时间: 2024年2月27日

修改时间: 2024年2月27日

概要

setuid() does not affect libuv s internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid().Impacts:This vulnerability affects all users in active release lines: 20.x, and 21.x.

CVSS v3 指标

NVD openEuler
CVSS评分 7.3
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity High
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-1087 setuid() does not affect libuv s internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid().Impacts:This vulnerability affects all users in active release lines: 20.x, and 21.x. 2024年2月27日

影响产品

产品 状态
KY3.4-4A nodejs Unaffected
KY3.4-5A nodejs Unaffected
KY3.5.1 nodejs Unaffected
KY3.5.2 nodejs Unaffected