CVE-2022-1348

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/05/2022
Last modified:
09/06/2025

Description

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:logrotate_project:logrotate:*:*:*:*:*:*:*:* 3.17.0 (including) 3.20.0 (excluding)
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*